Complete feed
Action required
Critical/high still unreviewed, or CISA KEV listed
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Critical [CVE-2026-18948] Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server
Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server. Red Hat rates this critical (CVSS 9.9). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-feature-server-rhel9:1787068065, rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786110033, rhoai/odh-feature-server-rhel9:1786107278. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.
Critical [CVE-2026-14450] Privilege escalation via forged HTTP headers due to missing authentication
Privilege escalation via forged HTTP headers due to missing authentication. Red Hat rates this important (CVSS 9.9). Weakness: CWE-290. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-maas-api-rhel9:1785850409, rhoai/odh-maas-api-rhel9:1787153683. Affected product named by the advisory: Red Hat OpenShift AI 3.4.
Critical [CVE-2026-66801] shared Kafka gh-spec topic Write ACL plus spoofable CloudEvent source enables fleet-wide cluster-admin from any compromised managed hub
shared Kafka gh-spec topic Write ACL plus spoofable CloudEvent source enables fleet-wide cluster-admin from any compromised managed hub. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-290. Red Hat lists fixing advisory RHSA-2026:54577 with package multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786621416, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786071343, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786067967, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1785773214.
Critical [CVE-2026-13206] Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command Injection. This issue affects WAH7601: through 20072026.
Critical [CVE-2026-28672] Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger: from 0.6 through 2.8.
Critical [CVE-2026-32227] SQL Injection vulnerability vulnerability in Apache Ranger
SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects. Users are recommended to upgrade to version 2.9.0, which fixes the issue.
Critical [CVE-2026-40920] Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0
Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.
Critical [CVE-2026-42537] Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue
Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.
Critical [CVE-2026-44416] Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0
Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.
Critical [CVE-2026-55799] Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue
Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.
High [CVE-2026-66806] TLS verification disabled when sending hub pull-secret to console.redhat.com
TLS verification disabled when sending hub pull-secret to console.redhat.com. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:59579 with package multicluster-engine/console-mce-rhel9:1787264250, rhacm2/console-rhel9:1787687062. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-72913] Arbitrary Code Execution via Chained DCS Escape Sequences
Arbitrary Code Execution via Chained DCS Escape Sequences. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: External Secrets Operator for Red Hat OpenShift; Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gvisor-tap-vsock.
High [CVE-2026-63622] swtpm privilege escalation via symlink following
swtpm privilege escalation via symlink following. Red Hat rates this important (CVSS 7.8). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: libvirt.
High [CVE-2026-18982] RHOAI fork aggregates training job create onto native edit/admin ClusterRoles
RHOAI fork aggregates training job create onto native edit/admin ClusterRoles. Red Hat rates this critical (CVSS 8.8). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-training-operator-rhel9:1787361677, rhoai/odh-training-operator-rhel9:1784814352, rhoai/odh-training-operator-rhel9:1785187053, rhoai/odh-training-operator-rhel9:1785188461. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.
High [CVE-2026-18951] [Trainer v2 Security] TRN-02: RHOAI overlay aggregates trainjobs CRUD into standard edit ClusterRole
[Trainer v2 Security] TRN-02: RHOAI overlay aggregates trainjobs CRUD into standard edit ClusterRole. Red Hat rates this critical (CVSS 8.8). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-training-operator-rhel9:1787361677, rhoai/odh-training-operator-rhel9:1784814352, rhoai/odh-training-operator-rhel9:1785188461. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.
High [CVE-2026-18950] Confused-deputy privilege escalation via unchecked roleRef in RoleBinding creation
Confused-deputy privilege escalation via unchecked roleRef in RoleBinding creation. Red Hat rates this critical (CVSS 8.8). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-dashboard-rhel9:1786109665, rhoai/odh-dashboard-rhel9:1785940823, rhoai/odh-dashboard-rhel9:1786109683. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.
High [CVE-2026-18949] ClusterRole grants cluster-wide CRUD on secrets and RBAC management resources
ClusterRole grants cluster-wide CRUD on secrets and RBAC management resources. Red Hat rates this critical (CVSS 8.8). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-dashboard-rhel9:1786109665, rhoai/odh-dashboard-rhel9:1785940823, rhoai/odh-dashboard-rhel9:1786109683. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI (RHOAI).
High [CVE-2026-18947] Authorization bypass in /materialize endpoints enables DoS via unauthorized full re-materialization
Authorization bypass in /materialize endpoints enables DoS via unauthorized full re-materialization. Red Hat rates this important (CVSS 8.5). Red Hat lists fixing advisory RHSA-2026:53263 with package rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786110033. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3.
High [CVE-2026-18941] Default authentication mode is no_auth — shared multi-tenant instances deployed without authentication
Default authentication mode is no_auth — shared multi-tenant instances deployed without authentication. Red Hat rates this important (CVSS 7.7). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786110033, rhoai/odh-feature-server-rhel9:1786107278. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.4.
High [CVE-2026-15581] TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide
TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide. Red Hat rates this important (CVSS 8). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-trustyai-service-operator-rhel9:1784993206, rhoai/odh-trustyai-service-operator-rhel9:1786614608, rhoai/odh-trustyai-service-operator-rhel9:1785187521, rhoai/odh-trustyai-service-operator-rhel9:1785187119. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.