Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-68391] hold reference for hci_conn in mgmt_pending_cmds
hold reference for hci_conn in mgmt_pending_cmds. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68374] add lock to bos_descriptors_read
add lock to bos_descriptors_read(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-68379] fix TIME_WAIT socket reference leak on PSP policy failure
fix TIME_WAIT socket reference leak on PSP policy failure. Red Hat rates this moderate (CVSS 7). Weakness: CWE-911. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: kernel.
High [CVE-2026-68181] access mei_device under device_lock on cleanup
access mei_device under device_lock on cleanup. Red Hat rates this moderate (CVSS 7). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
High [CVE-2026-48120] Remote Code Execution via malicious backup files
Remote Code Execution via malicious backup files. Red Hat rates this important (CVSS 8.6). Weakness: CWE-94.
High [CVE-2026-11425] Stored cross-site scripting allows administrator account takeover
Stored cross-site scripting allows administrator account takeover. Red Hat rates this important (CVSS 7.7). Weakness: CWE-79.
High [CVE-2026-19113] Unauthenticated denial of service via unbounded request body processing
Unauthenticated denial of service via unbounded request body processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-15972] Denial of Service via unbounded external gRPC connection acceptance
Denial of Service via unbounded external gRPC connection acceptance. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
High [CVE-2026-65819] Remote Denial of Service via crafted packet processing
Remote Denial of Service via crafted packet processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-805.
High [CVE-2026-19015] Uncontrolled resource consumption leading to denial of service
Uncontrolled resource consumption leading to denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-71556] Arbitrary file read/write via symbolic link resolution
Arbitrary file read/write via symbolic link resolution. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-20337 +6] ClamAV Vulnerabilities Affecting Cisco Products: August 2026
Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For additional information on these vulnerabilities in ClamAV, see the ClamAV blog. Cisco has released software updates that address these vulnerabilities in affected Cisco platforms. There are no workarounds that address these vulnerabilities. Notes: - The Security Impact Rating (SIR) for these vulnerabilities is High for Windows-based platforms only because those platforms run the ClamAV scanning process in a privileged security context. The platforms that are highly impacted include Cisco Secure Endpoint Connector for Windows. - The SIR for these vulnerabilities is Medium on other platforms, including Linux and Mac platforms, because those platforms run the ClamAV scanning process in a lower-privileged security context. The affected platforms include Secure Endpoint Connector for Linux and Mac. - Cisco Secure Endpoint Private Cloud itself is not impacted by these vulnerabilities. However, the Cisco Secure Endpoint Connector software that is distributed from the device is impacted.
High [CVE-2026-15816] root code execution via unescaped error message written to sourced emergency hook script in die
root code execution via unescaped error message written to sourced emergency hook script in die(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:54575 with package dracut-0:057-54.git20250423.el9_4.3, dracut-0:057-25.git20250717.el9_2.2, dracut-0:057-89.git20250311.el9_6.1, dracut-0:105-4.el10_0.1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; and 4 more.
High [CVE-2026-71559] Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0 before 1.5.0. Users of other language implementations are not affected. Users are recommended to upgrade to version 1.5.0, which fixes the issue.
High [CVE-2025-63235] codepr sol: Sol: Denial of service via resource exhaustion from malformed CONNECT packets
codepr sol: Sol: Denial of service via resource exhaustion from malformed CONNECT packets. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772.
High [CVE-2026-66032] Libssh2 Vulnerability in NetApp Products
Libssh2 versions through 1.11.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, ONTAP Select Deploy administration utility. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-66035] Libssh2 Vulnerability in NetApp Products
Libssh2 versions through 1.11.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-64531] Linux Kernel Vulnerability in NetApp Products
Certain Linux kernel versions are susceptible to a vulnerability referred to as OVSwrap which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-66033] Libssh2 Vulnerability in NetApp Products
Libssh2 versions through 1.11.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, ONTAP Select Deploy administration utility. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-70632] Arbitrary Code Execution in CFHD Decoder via Crafted AVI File
Arbitrary Code Execution in CFHD Decoder via Crafted AVI File. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).