Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.0Red Hat Updated

High [CVE-2026-80522] tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req

tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req(). Red Hat rates this important (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-80522
Linux Kernel
Aug 26, 2026
High7.0Red Hat Updated

High [CVE-2026-74744] inherit needed_headroom and needed_tailroom from phy_dev

inherit needed_headroom and needed_tailroom from phy_dev. Red Hat rates this important (CVSS 7). Weakness: CWE-124. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74744
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80585] only mark MPTFO subflows with SYN data

only mark MPTFO subflows with SYN data. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-80585
Linux Kernel
Aug 26, 2026
High7.0Red Hat Updated

High [CVE-2026-74743] inherit needed_headroom and needed_tailroom from lowerdev

inherit needed_headroom and needed_tailroom from lowerdev. Red Hat rates this important (CVSS 7). Weakness: CWE-124. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-74743
Linux Kernel
Aug 26, 2026
High7.0Red Hat Updated

High [CVE-2026-80586] reset DSS fields in case of unexpected size

reset DSS fields in case of unexpected size. Red Hat rates this important (CVSS 7). Weakness: CWE-824. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-80586
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80553] Cancel existing workqueues

Cancel existing workqueues. Red Hat rates this moderate (CVSS 7). Weakness: CWE-364. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-80553
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80558] Avoid using invalid osd indices from primary_temp

Avoid using invalid osd indices from primary_temp. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-80558
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80571] papr-phy-attest - validate cmd.length, plug mem leak

papr-phy-attest - validate cmd.length, plug mem leak. Red Hat rates this moderate (CVSS 7). Weakness: CWE-805. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-80571
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80582] Check VMA boundaries for PMD mappings

Check VMA boundaries for PMD mappings. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-80582
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-74737] Fix port_id extraction from SRC TAG

Fix port_id extraction from SRC TAG. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-74737
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80584] validate user buffer length in SNMP and ARP query ioctls

validate user buffer length in SNMP and ARP query ioctls. Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-80584
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80521] Unlink scc_entry in unix_del_edge

Unlink scc_entry in unix_del_edge(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: kernel.

CVE-2026-80521
Linux Kernel
Aug 26, 2026
High7.0Red Hat Updated

High [CVE-2026-74746] publish GC-visible tuple last

publish GC-visible tuple last. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74746
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80540] Fix UVD decode image min size calculation

Fix UVD decode image min size calculation. Red Hat rates this moderate (CVSS 7). Weakness: CWE-190.

CVE-2026-80540
Unclassified
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80589] stop the timeout timer when releasing a never added disk

stop the timeout timer when releasing a never added disk. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-80589
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80528] avoid fs reclaim while using current->journal_info

avoid fs reclaim while using current->journal_info. Red Hat rates this moderate (CVSS 7). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-80528
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80552] Ensure index for read/write regions are within range

Ensure index for read/write regions are within range. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-80552
Linux Kernel
Aug 26, 2026
High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-80561] fix multiple unsafe decodes in decode_locker

fix multiple unsafe decodes in decode_locker(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-80561
Linux Kernel
Aug 26, 2026
Critical9.1Apache Updated

Critical [CVE-2026-68525] Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET

Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fixes the issue.

CVE-2026-68525
Tomcat
Aug 25, 2026
Critical9.8Apache Updated

Critical [CVE-2026-65905] Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator

Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that request is replayable once only while the associated nonceCount remains within the replay window. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

CVE-2026-65905
Tomcat
Aug 25, 2026