Complete feed
Action required
Critical/high still unreviewed, or CISA KEV listed
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-15554] Authentication Bypass via AJP ssl_cert/is_ssl Forgery
Authentication Bypass via AJP ssl_cert/is_ssl Forgery. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 8.
High [CVE-2026-72693] Local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login
Local privilege escalation in openvt via incorrect process owner verification allowing passwordless root login. Red Hat rates this moderate (CVSS 7.8). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:41136 with package kbd-0:2.4.0-12.el9_8, kbd-0:2.6.4-8.el10_2, kbd-main-2.10.0-2.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-72694] MRTG daemon symlink-following chown allows local privilege escalation via PID file path manipulation
MRTG daemon symlink-following chown allows local privilege escalation via PID file path manipulation. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:57596 with package mrtg-0:2.17.10-12.el10_2.1, mrtg-0:2.17.7-12.el9_8.1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
High [CVE-2026-6726] MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reuse
MITRE: CVE-2026-6726 TPM 2.0 Improper Object Slot Reuse Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.
High [CVE-2026-62872] .NET Framework Elevation of Privilege Vulnerability
.NET Framework Elevation of Privilege Vulnerability Affected products named by the advisory: Microsoft.NET Framework 4.8 on Windows Server 2016; Microsoft.NET Framework 4.8 on Windows Server 2012 R2; Microsoft.NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016; Microsoft.NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012; and 4 more. Affected products named by the advisory: Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2; Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022; Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2025; Microsoft .NET Framework 3.5 on Windows Server 2012 R2.
High [CVE-2026-65810] .NET Framework Elevation of Privilege Vulnerability
.NET Framework Elevation of Privilege Vulnerability Affected products named by the advisory: Microsoft.NET Framework 4.8 on Windows Server 2016; Microsoft.NET Framework 4.8 on Windows Server 2012; Microsoft.NET Framework 4.8 on Windows Server 2012 R2; Microsoft.NET Framework 3.5 AND 4.8 on Windows Server 2019; and 4 more. Affected products named by the advisory: Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022; Microsoft .NET Framework 3.5 AND 4.7.2 on Windows Server 2019; Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016; Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012.
High [CVE-2026-70354] .NET Core Remote Code Execution Vulnerability
.NET Core Remote Code Execution Vulnerability Affected products named by the advisory: Microsoft.NET Framework 3.5 on Windows Server 2012; Microsoft.NET Framework 3.5 on Windows Server 2012 R2; Microsoft.NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2016; Microsoft.NET Framework 3.5 AND 4.7.2 on Windows Server 2019; and 4 more. Affected products named by the advisory: Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2019; Microsoft .NET Framework 3.5 AND 4.8 on Windows Server 2022; Microsoft .NET Framework 3.5 AND 4.8.1 on Windows Server 2022; Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 on Windows Server 2012 R2.
High [CVE-2026-4757] Code execution and privilege escalation via VAPIX API improper input validation
Code execution and privilege escalation via VAPIX API improper input validation. Red Hat rates this important (CVSS 7.2). Weakness: CWE-94. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: axis.
High [CVE-2026-66797] Velero Restore includes cluster-scoped RBAC resources with no exclusion — tampered backup yields hub cluster-admin
Velero Restore includes cluster-scoped RBAC resources with no exclusion — tampered backup yields hub cluster-admin. Red Hat rates this important (CVSS 8.5). Weakness: CWE-862. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/cluster-backup-rhel9-operator:1787684668, rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-66798] Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods
Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods. Red Hat rates this important (CVSS 8.8). Weakness: CWE-77. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/cluster-backup-rhel9-operator:1787684668, rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-66799] Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement
Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement. Red Hat rates this important (CVSS 7.1). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:60390 with package rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178, rhacm2/cluster-backup-rhel9-operator:1787259060. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-66800] CleanupAll triggers unguarded cluster-wide mass-delete via operator ServiceAccount
CleanupAll triggers unguarded cluster-wide mass-delete via operator ServiceAccount. Red Hat rates this important (CVSS 7.1). Weakness: CWE-862. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/cluster-backup-rhel9-operator:1787684668, rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-62901] .NET:.NET Denial of Service Vulnerability
.NET:.NET Denial of Service Vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Red Hat lists fixing advisory RHSA-2026:54542 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet8.0-0:8.0.130-1.el8_10, dotnet9.0-0:9.0.120-1.el9_6, dotnet10.0-0:10.0.111-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-62909] .NET:.NET Elevation of Privilege Vulnerability
.NET:.NET Elevation of Privilege Vulnerability. Red Hat rates this important (CVSS 7.8). Weakness: CWE-252. Red Hat lists fixing advisory RHSA-2026:54542 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet8.0-0:8.0.130-1.el8_10, dotnet9.0-0:9.0.120-1.el9_6, dotnet10.0-0:10.0.111-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-73266] tenant-controlled ClusterClaim labels propagated to ManagedCluster enabling cross-tenant ManagedClusterSet join
tenant-controlled ClusterClaim labels propagated to ManagedCluster enabling cross-tenant ManagedClusterSet join. Red Hat rates this important (CVSS 7.1). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/clusterclaims-controller-rhel9:1787259112, multicluster-engine/clusterclaims-controller-rhel9:1786577950, multicluster-engine/clusterclaims-controller-rhel9:1787239442, multicluster-engine/clusterclaims-controller-rhel9:1787259059. Affected product named by the advisory: Multicluster Engine for Kubernetes.
High [CVE-2026-73267] ManagedCluster deletion keyed solely on ClusterClaim.Spec.Namespace with no ownership check
ManagedCluster deletion keyed solely on ClusterClaim. Spec. Namespace with no ownership check. Red Hat rates this important (CVSS 7.7). Weakness: CWE-602. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/clusterclaims-controller-rhel9:1787259112, multicluster-engine/clusterclaims-controller-rhel9:1786577950, multicluster-engine/clusterclaims-controller-rhel9:1787239442, multicluster-engine/clusterclaims-controller-rhel9:1787259059. Affected products named by the advisory: multicluster engine for Kubernetes 2.10; multicluster engine for Kubernetes 2.11; multicluster engine for Kubernetes 2.17; multicluster engine for Kubernetes 2.6; and 2 more. Affected products named by the advisory: multicluster engine for Kubernetes 2.8; multicluster engine for Kubernetes 2.9.
Critical [CVE-2026-18948] Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server
Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server. Red Hat rates this critical (CVSS 9.9). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-feature-server-rhel9:1787068065, rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786110033, rhoai/odh-feature-server-rhel9:1786107278. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.
Critical [CVE-2026-14450] Privilege escalation via forged HTTP headers due to missing authentication
Privilege escalation via forged HTTP headers due to missing authentication. Red Hat rates this important (CVSS 9.9). Weakness: CWE-290. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-maas-api-rhel9:1785850409, rhoai/odh-maas-api-rhel9:1787153683. Affected product named by the advisory: Red Hat OpenShift AI 3.4.
Critical [CVE-2026-66801] shared Kafka gh-spec topic Write ACL plus spoofable CloudEvent source enables fleet-wide cluster-admin from any compromised managed hub
shared Kafka gh-spec topic Write ACL plus spoofable CloudEvent source enables fleet-wide cluster-admin from any compromised managed hub. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-290. Red Hat lists fixing advisory RHSA-2026:54577 with package multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786621416, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786071343, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786067967, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1785773214.
Critical [CVE-2026-13206] Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection. This issue affects WAH7601: through 20072026.