Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-19144] Arbitrary code execution via crafted HTML page
Arbitrary code execution via crafted HTML page. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-19142] Remote code execution via use after free in Views
Remote code execution via use after free in Views. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-19143] Google Chrome on Android: Sandbox escape via malicious WebAPK input
Google Chrome on Android: Sandbox escape via malicious WebAPK input. Red Hat rates this important (CVSS 8.2). Weakness: CWE-1286.
High [CVE-2026-19140] Sandbox escape via use after free vulnerability in crafted HTML.
Sandbox escape via use after free vulnerability in crafted HTML. Red Hat rates this important (CVSS 8.2). Weakness: CWE-825.
High [CVE-2026-19141] Sandbox escape due to use-after-free vulnerability
Sandbox escape due to use-after-free vulnerability. Red Hat rates this important (CVSS 8.2). Weakness: CWE-825.
High [CVE-2026-19138] Sandbox escape via heap buffer overflow in CrashReporting
Sandbox escape via heap buffer overflow in CrashReporting. Red Hat rates this important (CVSS 8.3). Weakness: CWE-120.
High [CVE-2026-19168] Arbitrary Code Execution via crafted HTML page
Arbitrary Code Execution via crafted HTML page. Red Hat rates this important (CVSS 8.8). Weakness: CWE-823.
High [CVE-2026-19169] Privilege escalation via crafted HTML page in Contextual Tasks
Privilege escalation via crafted HTML page in Contextual Tasks. Red Hat rates this important (CVSS 8.3). Weakness: CWE-79.
High [CVE-2026-19172] Sandbox escape via use after free in Views
Sandbox escape via use after free in Views. Red Hat rates this important (CVSS 8.2). Weakness: CWE-825.
High [CVE-2026-19170] Sandbox escape via use after free in WebGL
Sandbox escape via use after free in WebGL. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-19157] Sandbox escape via out-of-bounds write in Google Chrome on Android
Sandbox escape via out-of-bounds write in Google Chrome on Android. Red Hat rates this important (CVSS 8.4). Weakness: CWE-787.
High [CVE-2026-19149] Sandbox escape via use-after-free vulnerability in Aura
Sandbox escape via use-after-free vulnerability in Aura. Red Hat rates this important (CVSS 8.3). Weakness: CWE-825.
High [CVE-2026-67422] Denial of Service via Regular Expression Vulnerability
Denial of Service via Regular Expression Vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Affected products named by the advisory: Red Hat Developer Hub; Red Hat Hardened Images; Self-service automation portal 2.
High [CVE-2026-66808] unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection)
unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection). Red Hat rates this important (CVSS 8.7). Weakness: CWE-88. Red Hat lists fixing advisory RHSA-2026:54432 with package multicluster-engine/hypershift-addon-rhel9-operator:1786912006, multicluster-engine/hypershift-addon-rhel9-operator:1786548381, multicluster-engine/hypershift-addon-rhel9-operator:1787259113, multicluster-engine/hypershift-addon-rhel9-operator:1787264068. Affected product named by the advisory: Multicluster Engine for Kubernetes.
High [CVE-2026-71436] Denial of Service via invalid X-Axis parameters
Denial of Service via invalid X-Axis parameters. Red Hat rates this important (CVSS 7.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Dev Spaces.
High [CVE-2026-43632] Potential code execution via a race condition in tokenization endpoints
Potential code execution via a race condition in tokenization endpoints. Red Hat rates this important (CVSS 8.1). Weakness: CWE-364.
High [CVE-2026-43631] Remote code execution via use-after-free vulnerability in llama-server
Remote code execution via use-after-free vulnerability in llama-server. Red Hat rates this important (CVSS 8.1). Weakness: CWE-825.
High [CVE-2026-43629] Arbitrary code execution via crafted KV cache state files
Arbitrary code execution via crafted KV cache state files. Red Hat rates this important (CVSS 8.1). Weakness: CWE-787. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.
High [CVE-2026-43627] Arbitrary Code Execution via Integer Overflow in Memory Allocation
Arbitrary Code Execution via Integer Overflow in Memory Allocation. Red Hat rates this important (CVSS 7.8). Weakness: CWE-805. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.
High [CVE-2026-7867] Local Privilege Escalation via as-user option spoofing
Local Privilege Escalation via as-user option spoofing. Red Hat rates this important (CVSS 7.8). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:53435 with package udisks2-0:2.11.0-2.el10_2.1. Affected product named by the advisory: Red Hat Enterprise Linux 10.