Complete feed
Security advisories & CVEs
7794 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-76229] Arbitrary Command Injection via kustomize manager
Arbitrary Command Injection via kustomize manager. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-78.
Medium [CVE-2026-76217] Arbitrary File Read via Crafted Parameters
Arbitrary File Read via Crafted Parameters. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-88. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.
Medium [CVE-2026-16440] Denial of Service via crafted.class file
In Eclipse OpenJ9 versions up to 0.60, a crafted.class file with deeply nested annotations causes a segmentation fault. A remote attacker with low privileges could exploit this vulnerability by convincing a user to process a specially crafted `.class` file containing deeply nested annotations. This could lead to a segmentation fault, resulting in a Denial of Service (DoS) for the affected system. Red Hat severity: Moderate — CVSS 5.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 8. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: java-1.8.0-ibm.
Medium [CVE-2026-76166] mod_cluster Advertise Listener: unauthenticated DoS via crafted multicast datagram
mod_cluster Advertise Listener: unauthenticated DoS via crafted multicast datagram. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-476. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat JBoss Web Server 6; and 2 more. Affected products named by the advisory: Red Hat JBoss Web Server 7; Red Hat Single Sign-On 7.
Medium [CVE-2026-75900] Out-of-bounds read in SWTPM_NVRAM_CheckHeader due to sizeof(pointer) vs sizeof(struct) mismatch
Out-of-bounds read in SWTPM_NVRAM_CheckHeader due to sizeof(pointer) vs sizeof(struct) mismatch. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Low [CVE-2026-76891] Denial of Service via sharkd crash
Denial of Service via sharkd crash. Red Hat rates this low (CVSS 3.1). Weakness: CWE-248. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Low [CVE-2026-76885] Denial of Service via Tektronix K12xx file parsing
Denial of Service via Tektronix K12xx file parsing. Red Hat rates this low (CVSS 3.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Low [CVE-2026-76888] Heap-based Buffer Overflow in RDP dissector leads to Denial of Service
Heap-based Buffer Overflow in RDP dissector leads to Denial of Service. Red Hat rates this low (CVSS 3.1). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Low [CVE-2026-76887] Denial of service via heap-based buffer overflow in dissection engine
Denial of service via heap-based buffer overflow in dissection engine. Red Hat rates this low (CVSS 3.1). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Low [CVE-2026-76884] Denial of Service via ERF file parser crash
Denial of Service via ERF file parser crash. Red Hat rates this low (CVSS 3.3). Weakness: CWE-130. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Low [CVE-2026-76369] Path Traversal through Automation Broker in Splunk SOAR
In Splunk SOAR versions below 8.6.0, a user who holds the OnPrem Broker role could write files outside the intended Automation Broker log directory. The vulnerability is possible because Automation Broker log uploads accept crafted filename input before writing log files. For more information see Manage roles and permissions in Splunk SOAR (Cloud) ( ) and About Splunk SOAR Automation Broker ( ) in the Splunk documentation.
Low [CVE-2026-76368] Missing Authorization through Playbooks in Splunk SOAR
In Splunk SOAR versions below 8.6.0, a user who holds a role that contains the playbooks:view permission could view metadata about a playbook repository that they are not authorized to view. The vulnerability is possible because Playbook History does not check repository permissions before returning playbook revision metadata. For more information see Manage roles and permissions in Splunk SOAR (Cloud) ( ) and Manage settings for a playbook in Splunk SOAR (Cloud) ( ) in the Splunk documentation.
Low [CVE-2026-76361] Server-Side Request Forgery (SSRF) through the Connectivity Check REST API in Splunk SOAR
In Splunk SOAR versions below 8.6.0, a user with the "Administrator" role could use the /rest/support/connectivity/.../check_connectivity endpoint to make Splunk SOAR initiate outbound network connections to arbitrary destinations and determine whether internal hosts and ports are reachable. The Server-Side Request Forgery (SSRF) is possible because the connectivity check REST API does not sufficiently validate the destination before Splunk SOAR connects to it. For more information see Manage roles and permissions in Splunk SOAR (On-premises) ( ) in the Splunk documentation.
Low [CVE-2026-76348] Missing Authorization in Search Head Cluster Member Controls in Splunk Enterprise
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who holds a Splunk role that contains the high-privilege list_search_head_clustering capability could send a read request to Search Head Cluster member control endpoints and change cluster state, which could allow for a denial of service. The vulnerability is possible because the Search Head Cluster member control endpoints do not require a state-changing Hypertext Transfer Protocol (HTTP) request type before they apply read-only authorization.
Critical [CVE-2026-21580] This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server
This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server. This Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability, with a CVSS Score of 8.6, allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser, perform actions as a higher-privileged user, and to get into the system utilizing loopholes exposed from security best-practices being overlooked. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.21 See the release notes ([ ]). This vulnerability was reported via our Bug Bounty program. Affected products named by the advisory: Confluence Server.
Critical [CVE-2026-76044] Arbitrary code execution due to a race condition in USB
Arbitrary code execution due to a race condition in USB. Red Hat rates this important (CVSS 9). Weakness: CWE-368.
Critical [CVE-2026-66780] flat broker trust model grants every spoke full CRUD on all endpoints, secrets, and endpointslices in broker namespace
flat broker trust model grants every spoke full CRUD on all endpoints, secrets, and endpointslices in broker namespace. Red Hat rates this important (CVSS 9.9). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/submariner-addon-rhel9:1787362694, rhacm2/submariner-addon-rhel9:1787689013, rhacm2/submariner-addon-rhel9:1787365971, rhacm2/submariner-addon-rhel9:1787362658. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Critical [CVE-2026-18963] Unauthenticated account takeover via reset-credentials flow bypass
Unauthenticated account takeover via reset-credentials flow bypass. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-640. Red Hat lists fixing advisory RHSA-2026:56524 with package rhbk/keycloak-rhel9:26.6-12, rhbk-keycloak-rhel9/rhbk-keycloak-rhel9, keycloak-services, rhbk-openshift-rhel9/rhbk-openshift-rhel9. Affected products named by the advisory: Red Hat build of Keycloak 26.4; Red Hat build of Keycloak 26.6.
Critical [CVE-2026-12564] Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credential ssrf
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. An authenticated attacker with credential-creation privileges can exfiltrate the service account token, gaining Kubernetes API access to the control plane namespaces with full pod CRUD and secret read permissions, including database credentials and the Django SECRET_KEY. The vulnerability is particularly impactful in AAP Cloud (managed service) environments where the Kubernetes control plane is managed by Red Hat and tenant isolation is a security boundary. On-premise deployments are also affected, though the impact is lower since the administrator already has access to the infrastructure. The vulnerable code path exists in all AAP versions that ship the hashivault credential plugin with kubernetes_role authentication support. Red Hat severity: Critical — CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N). Weakness: CWE-918. Affected Red Hat products: Red Hat Ansible Automation Platform 2. Red Hat does not currently list a fixing RHSA for this CVE.
Critical [CVE-2026-34884] SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP
SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue.