Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-74949] Privilege escalation due to use-after-free in the Graphics: Canvas2D component
Privilege escalation due to use-after-free in the Graphics: Canvas2D component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-74943] Use-after-free in the Graphics: ImageLib component
Use-after-free in the Graphics: ImageLib component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-74942] Privilege escalation in the Remote Settings Client component
Privilege escalation in the Remote Settings Client component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-74944] Use-after-free in the DOM: Core & HTML component
Use-after-free in the DOM: Core & HTML component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-74945] Information disclosure in the Graphics: Text component
Information disclosure in the Graphics: Text component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-201. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-74941] Privilege escalation in the Graphics: CanvasWebGL component
Privilege escalation in the Graphics: CanvasWebGL component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-74940] Use-after-free in the Graphics: Text component
Use-after-free in the Graphics: Text component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-74939] Privilege escalation in the DOM: Navigation component
Privilege escalation in the DOM: Navigation component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-74934] Site isolation issue in the Graphics: CanvasWebGL component
Site isolation issue in the Graphics: CanvasWebGL component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-653. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-74936] Use-after-free in the JavaScript: WebAssembly component
Use-after-free in the JavaScript: WebAssembly component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-74935] Privilege escalation in the DOM: Networking component
Privilege escalation in the DOM: Networking component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-75838] Cross-Site Scripting via IN_PLACE sanitization
Cross-Site Scripting via IN_PLACE sanitization. Red Hat rates this important (CVSS 7.3). Weakness: CWE-79. Affected products named by the advisory: Migration Toolkit for Virtualization; Multicluster Engine for Kubernetes; Node HealthCheck Operator; OpenShift Service Mesh 3; and 15 more. Affected products named by the advisory: Red Hat 3scale API Management Platform 2; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Advanced Cluster Security 4; Red Hat Ansible Automation Platform 2; and 11 more.
High [CVE-2026-70906] Improve font loading (2026-08 Security Update)
Improve font loading (2026-08 Security Update). Red Hat rates this moderate (CVSS 7.5). Red Hat lists fixing advisory RHSA-2026:55799 with package java-25-openjdk-portable, java-25-openjdk-1:25.0.4.1.1-1.1.el9, java-25-openjdk-windows, java-25-openjdk-main-25.0.4.1.1-1.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
Medium [CVE-2026-71084] Denial of Service via unauthenticated local access
Denial of Service via unauthenticated local access. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: mysql-connector-odbc.
Medium [CVE-2026-71079] Denial of Service via network access by a low privileged attacker
Denial of Service via network access by a low privileged attacker. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat package: mysql-connector-odbc.
Medium [CVE-2026-76042] Information disclosure via uninitialized resource in GPU
Information disclosure via uninitialized resource in GPU. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-824.
Medium [CVE-2026-16732] Request spoofing via numeric trustProxy configuration
Request spoofing via numeric trustProxy configuration. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-501. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces.
Medium [CVE-2026-18504] Schema validation bypass via root primitive coercion mismatch
Schema validation bypass via root primitive coercion mismatch. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces.
Medium [CVE-2026-49452] CSS Injection via Presentational Hints
WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-hint attribute values into CSS in weasyprint/css/__init__.py when presentational_hints=True. The background attribute is inserted into a background-image:url() declaration and parsed by tinycss2.parse_blocks_contents(), allowing untrusted HTML to inject additional CSS declarations. Applications that render untrusted HTML with presentational hints enabled can be affected by CSS injection and server-side requests through injected url() values. This issue is fixed in version 69.0. This vulnerability allows a remote attacker to inject arbitrary CSS, potentially leading to information disclosure or the initiation of server-side requests through specially crafted url() values. Red Hat Ansible Automation Platform 2.5 ships WeasyPrint 69.0, which already includes the fix for this vulnerability, and is therefore not affected. The WeasyPrint package in EPEL ships a version within the vulnerable range. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-79.
Medium [CVE-2026-66781] IPsec PSK stored cleartext in Submariner CR spec
IPsec PSK stored cleartext in Submariner CR spec. Red Hat rates this important (CVSS 6.5). Weakness: CWE-312. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/submariner-addon-rhel9:1787362694, rhacm2/submariner-addon-rhel9:1787689013, rhacm2/submariner-addon-rhel9:1787365971, rhacm2/submariner-addon-rhel9:1787362658. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.