Complete feed
Security advisories & CVEs
7797 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-61308] Enhance HTTP Connections (2026-08 Security Update)
Enhance HTTP Connections (2026-08 Security Update). Red Hat rates this moderate (CVSS 6.8). Red Hat lists fixing advisory RHSA-2026:55788 with package java-21-openjdk-portable-main-21.0.12.1.1-0.1.hum1, java-25-openjdk-1:25.0.4.1.1-1.1.el9, java-25-openjdk-windows, java-25-openjdk-main-25.0.4.1.1-1.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.
Medium [CVE-2026-70907] Enhance TLS server (2026-08 Security Update)
Enhance TLS server (2026-08 Security Update). Red Hat rates this moderate (CVSS 5.3). Red Hat lists fixing advisory RHSA-2026:55788 with package java-21-openjdk-portable-main-21.0.12.1.1-0.1.hum1, java-25-openjdk-1:25.0.4.1.1-1.1.el9, java-25-openjdk-windows, java-25-openjdk-main-25.0.4.1.1-1.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.
Low [CVE-2026-63632] Denial of Service via out-of-bounds read in version converter
Denial of Service via out-of-bounds read in version converter. Red Hat rates this low (CVSS 3.3). Weakness: CWE-125. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
Low [CVE-2026-74985] Privilege escalation in the Enterprise Policies component
Privilege escalation in the Enterprise Policies component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-266.
Low [CVE-2026-74986] Site isolation issue in the CSS Parsing and Computation component
Site isolation issue in the CSS Parsing and Computation component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-501.
Low [CVE-2026-74984] Race condition in the JavaScript Engine component
Race condition in the JavaScript Engine component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-366.
Low [CVE-2026-74981] Site isolation issue in the Audio/Video: Web Codecs component
Site isolation issue in the Audio/Video: Web Codecs component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-501.
Low [CVE-2026-74980] Clickjacking issue in the Downloads component in Firefox for Android
Clickjacking issue in the Downloads component in Firefox for Android. Red Hat rates this low (CVSS 3.4). Weakness: CWE-1021.
Low [CVE-2026-74982] Denial-of-service in the Widget component
Denial-of-service in the Widget component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-770.
Low [CVE-2026-74977] Integer overflow in the Graphics component
Integer overflow in the Graphics component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-190.
Low [CVE-2026-74978] Clickjacking issue in the Widget component
Clickjacking issue in the Widget component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-1021.
Low [CVE-2026-74979] Mitigation bypass in the Add-ons Manager component
Mitigation bypass in the Add-ons Manager component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-807.
Low [CVE-2026-74975] Spoofing issue in the Downloads component in Firefox for Android
Spoofing issue in the Downloads component in Firefox for Android. Red Hat rates this low (CVSS 3.4). Weakness: CWE-494.
Low [CVE-2026-74983] Mitigation bypass in the Data Loss Prevention component
Mitigation bypass in the Data Loss Prevention component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-807. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Low [CVE-2026-74976] JIT miscompilation in the JavaScript Engine: JIT component
JIT miscompilation in the JavaScript Engine: JIT component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-733. Red Hat lists fixing advisory RHSA-2026:58897 with package firefox-0:140.14.0-1.el10_2, firefox-0:140.14.0-1.el8_10, firefox-0:140.14.0-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Low [CVE-2026-23938] Denial of Service via crafted JavaScript scripts
Denial of Service via crafted JavaScript scripts. Red Hat rates this low (CVSS 2.7). Weakness: CWE-770.
Low [CVE-2026-60589] Improve Resource Resolving (2026-08 Security Update)
Improve Resource Resolving (2026-08 Security Update). Red Hat rates this moderate (CVSS 3.7). Red Hat lists fixing advisory RHSA-2026:55788 with package java-21-openjdk-portable-main-21.0.12.1.1-0.1.hum1, java-25-openjdk-1:25.0.4.1.1-1.1.el9, java-25-openjdk-windows, java-25-openjdk-main-25.0.4.1.1-1.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.
Critical [CVE-2026-66795] CSR auto-approver does not validate certificate Subject, signerName, or requester identity
CSR auto-approver does not validate certificate Subject, signerName, or requester identity. Red Hat rates this important (CVSS 9.1). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/managedcluster-import-controller-rhel9:1787078307, multicluster-engine/managedcluster-import-controller-rhel9:1786577915, multicluster-engine/managedcluster-import-controller-rhel9:1787260779, multicluster-engine/managedcluster-import-controller-rhel9:1787259044. Affected product named by the advisory: Multicluster Engine for Kubernetes.
Critical [CVE-2026-19478] GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.
Critical [CVE-2026-71472] Shell-command and SQL injection in postgresql-start.sh via CR-supplied WORK_MEM
Shell-command and SQL injection in postgresql-start.sh via CR-supplied WORK_MEM. Red Hat rates this important (CVSS 9.1). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-rhel9:1787682033, rhacm2/acm-search-v2-rhel9:1787681674, rhacm2/acm-search-v2-rhel9:1787681686, rhacm2/acm-search-v2-rhel9:1787682112. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.