Complete feed
Security advisories & CVEs
3253 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-67189] pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX responses and rendered as HTML through a DOM sink in the administrator interface
pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature, where PTR records returned by reverse DNS lookups are incorporated without sanitization into AJAX responses and rendered as HTML through a DOM sink in the administrator interface. An attacker who controls a PTR record and generates sufficient traffic to appear as a top talker can execute arbitrary JavaScript in an administrator's browser, gaining access to the authenticated session context and same-origin access to the firewall management interface, enabling account creation and arbitrary OS command execution.
Medium [CVE-2026-69159] Out-of-bounds read leads to denial of service and information disclosure
Out-of-bounds read leads to denial of service and information disclosure. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: freerdp.
Medium [CVE-2026-63652] Denial of Service and heap corruption via malformed RDP audio PDU
Denial of Service and heap corruption via malformed RDP audio PDU. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-1341. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: freerdp.
Medium [CVE-2026-63117] Denial of Service via ADPCM frame size calculation
Denial of Service via ADPCM frame size calculation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-369. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: freerdp.
Medium [CVE-2026-18874] annotation values rendered into YAML via text/template without escaping allows YAML injection into Subscription
annotation values rendered into YAML via text/template without escaping allows YAML injection into Subscription. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-volsync-addon-controller-rhel9:1787266360, rhacm2/acm-volsync-addon-controller-rhel9:1787683560, rhacm2/acm-volsync-addon-controller-rhel9:1787266556, rhacm2/acm-volsync-addon-controller-rhel9:1787266564. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Medium [CVE-2026-55648] Integer overflow allows out-of-bounds read via malicious RDP server
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy_from_icon_data in libfreerdp/codec/color.c calculates nWidth multiplied by nHeight multiplied by FreeRDPGetBytesPerPixel(format) in 32-bit arithmetic. A malicious RDP server can send a RAIL TS_ICON_INFO update with dimensions such as 32768 by 32768 and 32 bits per pixel so the required-size calculation wraps, bypassing the cbBitsColor source bounds check before freerdp_image_copy_no_overlap reads attacker-controlled icon data. This affects RemoteApp clients using the vulnerable library path, while xfreerdp has a caller-side mitigation. This issue is fixed in version 3.27.0. An integer overflow vulnerability in the `freerdp_image_copy_from_icon_data` function allows a malicious Remote Desktop Protocol (RDP) server to bypass a bounds check. By sending a specially crafted icon update with large dimensions, the server can cause the client to read attacker-controlled data beyond the intended memory buffer. This out-of-bounds read can lead to information disclosure or potentially arbitrary code execution on affected RemoteApp clients. Red Hat severity: Moderate — CVSS 4.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L). Weakness: CWE-125.
Medium [CVE-2026-55564] Out-of-bounds read in glyph cache leads to denial of service and information disclosure
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_cache_get function in libfreerdp/cache/glyph.c checks whether index is greater than cache->number instead of greater than or equal to it. A malicious RDP server can use GLYPH_FRAGMENT_USE replay in update_process_glyph_fragments to make the default cache receive index 254 when cache->number is 254, reading one pointer beyond the entries array and dereferencing it as a glyph. This can crash the client and may disclose adjacent heap data. This issue is fixed in version 3.27.0. A flaw was found in FreeRDP. A malicious Remote Desktop Protocol (RDP) server can exploit an out-of-bounds read vulnerability in the glyph_cache_get function. By sending crafted glyph fragments, the server can cause the client to read beyond the intended memory buffer. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: freerdp.
Medium [CVE-2026-75145] Out-of-bounds memory access due to integer narrowing conversion
Out-of-bounds memory access due to integer narrowing conversion. Red Hat rates this moderate (CVSS 5.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-20232] Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of another user. To exploit this vulnerability, the attacker must have valid user credentials on the affected system. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. Affected product named by the advisory: Industrial Ethernet Switches.
Medium [CVE-2026-20314] Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability
A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Medium [CVE-2026-20327] Cisco Unified Intelligence Center SQL Injection Vulnerability
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to read the contents of the internal database of an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Medium [CVE-2026-20177] Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability
A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an unauthenticated, remote attacker to cause the device manager, SSH, or API to become inaccessible. This vulnerability is due to insufficient protection against management plane flooding attacks. An attacker could exploit this vulnerability by sending a high rate of ICMP, SSH, or HTTP traffic to an affected device. A successful exploit could allow the attacker to cause the CPU of the device to increase, resulting in a denial of service (DoS) condition on the device manager web GUI, SSH, or API. Data traffic through the device is not affected. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. Affected product named by the advisory: Industrial Ethernet Switches.
Medium [CVE-2026-20302] Cisco RoomOS Stack Overflow Vulnerability
A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected device to execute arbitrary code with root privileges. This vulnerability is due to insufficient boundary checks for specific data that is provided through the USB driver. An attacker could exploit this vulnerability by connecting a malicious USB device to an affected device. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected system and execute arbitrary code with root privileges. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. Affected product named by the advisory: RoomOS Software.
Medium [CVE-2026-76878] aodh / python-watcher: cross-project alarm enumeration and webhook missing authorization
aodh / python-watcher: cross-project alarm enumeration and webhook missing authorization. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-863. Affected products named by the advisory: Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-76231] Arbitrary command execution via unsanitized dependency names
Arbitrary command execution via unsanitized dependency names. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-78.
Medium [CVE-2026-76228] Arbitrary Code Execution via malicious Gradle Wrapper properties
Arbitrary Code Execution via malicious Gradle Wrapper properties. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-78.
Medium [CVE-2026-76229] Arbitrary Command Injection via kustomize manager
Arbitrary Command Injection via kustomize manager. Red Hat rates this moderate (CVSS 6.7). Weakness: CWE-78.
Medium [CVE-2026-76217] Arbitrary File Read via Crafted Parameters
Arbitrary File Read via Crafted Parameters. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-88. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat Satellite 6.
Medium [CVE-2026-16440] Denial of Service via crafted.class file
In Eclipse OpenJ9 versions up to 0.60, a crafted.class file with deeply nested annotations causes a segmentation fault. A remote attacker with low privileges could exploit this vulnerability by convincing a user to process a specially crafted `.class` file containing deeply nested annotations. This could lead to a segmentation fault, resulting in a Denial of Service (DoS) for the affected system. Red Hat severity: Moderate — CVSS 5.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 8. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: java-1.8.0-ibm.
Medium [CVE-2026-76166] mod_cluster Advertise Listener: unauthenticated DoS via crafted multicast datagram
mod_cluster Advertise Listener: unauthenticated DoS via crafted multicast datagram. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-476. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat JBoss Web Server 6; and 2 more. Affected products named by the advisory: Red Hat JBoss Web Server 7; Red Hat Single Sign-On 7.