Complete feed
Security advisories & CVEs
3245 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-43961] Vimscript injection via unescaped filename in netrw s:NetrwMarkFile filter expression allows arbitrary code execution
Vimscript injection via unescaped filename in netrw s:NetrwMarkFile() filter() expression allows arbitrary code execution. Red Hat rates this important (CVSS 7.8). Weakness: CWE-94.
High [CVE-2026-19489] Vulnerability in NetScaler ADC and NetScaler Gateway
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
High [CVE-2026-76235] unauthenticated remote memory leak via CockpitLang cookie in send_login_html
unauthenticated remote memory leak via CockpitLang cookie in send_login_html. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-401. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-58081] Heap-based buffer overflow in encoding modules
Several encoding modules, including HZ, UTF-7, VIQR, and ZW, did not properly check the size of the caller-supplied output buffer before writing converted characters. An application that uses iconv(3) to convert untrusted input to or from one of the affected encodings may be vulnerable to buffer overflows if it uses one of the affected encoding modules. A flaw was found in iconv. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: php.
Medium [CVE-2026-76928] Denial of Service via X.509IF protocol dissector crash
Denial of Service via X.509IF protocol dissector crash. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76924] Denial of Service via Out-of-bounds Read in Kerberos Dissector
Denial of Service via Out-of-bounds Read in Kerberos Dissector. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76923] Denial of Service due to out-of-bounds read in Bluetooth HFP dissector
Denial of Service due to out-of-bounds read in Bluetooth HFP dissector. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76918] Denial of Service via SSH protocol dissector crash
Denial of Service via SSH protocol dissector crash. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-248. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76917] Denial of Service via Heap-based Buffer Overflow in Bluetooth AVRCP Dissector
Denial of Service via Heap-based Buffer Overflow in Bluetooth AVRCP Dissector. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76880] Denial of Service via RRC protocol dissector out-of-bounds write
Denial of Service via RRC protocol dissector out-of-bounds write. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: wireshark.
Medium [CVE-2026-76879] Denial of Service via C12.22 protocol dissector crash
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service By sending a specially crafted network packet or capture file, an attacker can crash the application, disrupting network analysis capabilities. RHEL 9 and older versions are not affected. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-617. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: wireshark.
Medium [CVE-2026-76889] Denial of Service via UMTS FP protocol dissector crash
Denial of Service via UMTS FP protocol dissector crash. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-617. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76886] Denial of Service via C12.22 protocol dissector crash
C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service A flaw was found in Wireshark. An unauthenticated remote attacker could exploit a vulnerability in the C12.22 protocol dissector by sending specially crafted network traffic. This could lead to a crash of the application, resulting in a Denial of Service (DoS). Exploitation requires user interaction, such as opening a malicious file, limiting its impact in typical Red Hat deployments where Wireshark is used for network analysis rather than as a continuously exposed service. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-617. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: wireshark.
Medium [CVE-2026-76883] Denial of Service via heap-based buffer overflow in Catapult DCT2000 file parser
Denial of Service via heap-based buffer overflow in Catapult DCT2000 file parser. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76882] Denial of Service via Bluetooth Attribute Protocol dissector out-of-bounds read
Denial of Service via Bluetooth Attribute Protocol dissector out-of-bounds read. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76881] Denial of service via CMS protocol dissector crash
Denial of service via CMS protocol dissector crash. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: wireshark.
Medium [CVE-2026-76405] Information Disclosure through Cleartext Storage in the App Key Value Store in the Splunk On-Call (VictorOps) app
In Splunk On-Call (VictorOps) app versions below 1.0.43 on Splunkbase, a user who does not hold the "admin" or "power" Splunk roles could read a partially masked Application Programming Interface (API) key from the App Key Value Store (KV Store). The exposure is possible because the Splunk On-Call (VictorOps) app does not fully mask the API key before storing it in a KV Store collection that the user can read. For more information see About the app key value store ( ) in the Splunk documentation.
Medium [CVE-2026-76401] Regular Expression Denial of Service (DoS) through the REST API in Splunk Connect for Kafka
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure timestamp extraction with a crafted regular expression and matching event data to block a Kafka Connect worker thread, stopping event delivery for the affected connector. The vulnerability is possible because timestamp extraction evaluates customer-supplied regular expressions without a time limit. For more information see Install Splunk Connect for Kafka ( ) and Data ingestion parameters for Splunk Connect for Kafka ( ) in the Splunk documentation.
Medium [CVE-2026-76400] Denial of Service (DoS) through the REST API in Splunk Connect for Kafka
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API and influence responses from a Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise could cause the connector to retry failed event batches until event delivery stops. The vulnerability is possible because HTTP Event Collector delivery retry handling uses an unbounded default for failed batches instead of a finite retry limit. For more information see Install Splunk Connect for Kafka ( ), Data ingestion parameters for Splunk Connect for Kafka ( ), and Set up and use HTTP Event Collector with configuration files ( ) in the Splunk documentation.
Medium [CVE-2026-76398] Improper Access Control during Experiment History Deletion through the REST API in Splunk AI Toolkit
In Splunk AI Toolkit versions below 6.0.1, a user who does not hold the "admin" or "power" Splunk roles could delete the experiment history of another user without permission through the Representational State Transfer (REST) API. The vulnerability is possible because Splunk AI Toolkit deletes experiment history before it verifies that the user can delete the associated experiment. For more information see Experiment Assistants ( ) in the Splunk documentation.