Complete feed
Action required
Critical/high still unreviewed, or CISA KEV listed
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-61361] Windows DHCP Client Remote Code Execution Vulnerability
Windows DHCP Client Remote Code Execution Vulnerability Affected product named by the advisory: Windows Server 2025.
High [CVE-2026-61346] Windows Graphics Kernel Elevation of Privilege Vulnerability
Windows Graphics Kernel Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.
High [CVE-2026-59132] Windows TCP/IP Denial of Service Vulnerability
Windows TCP/IP Denial of Service Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
High [CVE-2026-49179] Windows Active Directory Domain Services Remote Code Execution Vulnerability
Windows Active Directory Domain Services Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
High [CVE-2026-54984] Windows Imaging Component Remote Code Execution Vulnerability
Windows Imaging Component Remote Code Execution Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
High [CVE-2026-54113] Remote Procedure Call Denial of Service Vulnerability
Remote Procedure Call Denial of Service Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 1 more. Affected products named by the advisory: Windows Server 2012.
High [CVE-2026-57105] Microsoft Office SharePoint Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. Affected products named by the advisory: Microsoft SharePoint Server 2019; Microsoft SharePoint Server Subscription Edition.
High [CVE-2026-56174] Windows Narrator Braille Elevation of Privilege Vulnerability
Windows Narrator Braille Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.
High [CVE-2026-50472] Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability
Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025; Windows Server 2016; and 2 more. Affected products named by the advisory: Windows Server 2012 R2.
High [CVE-2026-73088] Prototype pollution leading to denial of service
Prototype pollution leading to denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:56338 with package ansible-automation-platform/automation-portal:1787047114, grafana13-1-main-13.1.3-0.1.1.hum1, discovery/discovery-ui-rhel9:1786634825, ansible-automation-platform/automation-portal:1787047188. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Gatekeeper 3; Migration Toolkit for Containers; and 43 more. Affected products named by the advisory: Node HealthCheck Operator; OpenShift Lightspeed; OpenShift Pipelines; OpenShift Service Mesh 3; and 39 more.
High [CVE-2026-73086] Predictable ID generation due to integer overflow
Predictable ID generation due to integer overflow. Red Hat rates this important (CVSS 7.4). Weakness: CWE-1241. Red Hat lists fixing advisory RHSA-2026:56338 with package multicluster-engine/console-mce-rhel9:1787079359, rhacm2/console-rhel9:1787339248, jaeger-main-2.20.0-0.8.hum1, multicluster-engine/console-mce-rhel9:1787264250. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Gatekeeper 3; Migration Toolkit for Containers; and 39 more. Affected products named by the advisory: Multicluster Engine for Kubernetes; Network Observability Operator; Node HealthCheck Operator; OpenShift Lightspeed; and 35 more.
High [CVE-2026-20349] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. Affected products named by the advisory: Firepower 2100 Series; Firepower 1000 Series; ASA 5500-X Series Firewalls; 3000 Series Industrial Security Appliances (ISA); and 3 more.
High [CVE-2025-35973] Privilege escalation in Ring 0 via improper value handling
Privilege escalation in Ring 0 via improper value handling. Red Hat rates this important (CVSS 7.2). Weakness: CWE-266. Affected products named by the advisory: Confidential Compute Attestation; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat OpenShift Container Platform 4; and 1 more.
High [CVE-2026-73078] Arbitrary Code Execution via Crafted Netrw Menu Entries
Arbitrary Code Execution via Crafted Netrw Menu Entries. Red Hat rates this important (CVSS 8.8). Weakness: CWE-77.
High [CVE-2026-73077] Arbitrary Code Execution via Insecure Shell Command Handling
Arbitrary Code Execution via Insecure Shell Command Handling. Red Hat rates this important (CVSS 7.3). Weakness: CWE-78.
High [CVE-2026-73076] Arbitrary command execution via crafted vimball
Arbitrary command execution via crafted vimball. Red Hat rates this important (CVSS 7.3). Weakness: CWE-78.
High [CVE-2026-73072] Heap buffer overflow allows arbitrary code execution
Heap buffer overflow allows arbitrary code execution. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: vim.
High [CVE-2026-14380 +1] Incomplete fix for CVE-2026-14380 DBI: Arbitrary code execution via caller-influenced Profile attribute
Incomplete fix for CVE-2026-14380 DBI: Arbitrary code execution via caller-influenced Profile attribute. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: perl-dbi.
High [CVE-2026-73066] Heap out-of-bounds write via crafted.traineddata
Heap out-of-bounds write via crafted.traineddata. Red Hat rates this important (CVSS 7.1). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: tesseract.
High [CVE-2026-18129] Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections
Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.