Skip to content
VulniPulse

Complete feed

Security advisories & CVEs

1320 advisories across 32 monitored vendors.

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.8Red Hat

High [CVE-2026-62909] .NET:.NET Elevation of Privilege Vulnerability

.NET:.NET Elevation of Privilege Vulnerability. Red Hat rates this important (CVSS 7.8). Weakness: CWE-252. Red Hat lists fixing advisory RHSA-2026:54542 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet8.0-0:8.0.130-1.el8_10, dotnet9.0-0:9.0.120-1.el9_6, dotnet10.0-0:10.0.111-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-62909
Unclassified
Aug 11, 2026
High7.1Red Hat

High [CVE-2026-73266] tenant-controlled ClusterClaim labels propagated to ManagedCluster enabling cross-tenant ManagedClusterSet join

tenant-controlled ClusterClaim labels propagated to ManagedCluster enabling cross-tenant ManagedClusterSet join. Red Hat rates this important (CVSS 7.1). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/clusterclaims-controller-rhel9:1787259112, multicluster-engine/clusterclaims-controller-rhel9:1786577950, multicluster-engine/clusterclaims-controller-rhel9:1787239442, multicluster-engine/clusterclaims-controller-rhel9:1787259059. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-73266
Unclassified
Aug 11, 2026
High7.7Red Hat

High [CVE-2026-73267] ManagedCluster deletion keyed solely on ClusterClaim.Spec.Namespace with no ownership check

ManagedCluster deletion keyed solely on ClusterClaim. Spec. Namespace with no ownership check. Red Hat rates this important (CVSS 7.7). Weakness: CWE-602. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/clusterclaims-controller-rhel9:1787259112, multicluster-engine/clusterclaims-controller-rhel9:1786577950, multicluster-engine/clusterclaims-controller-rhel9:1787239442, multicluster-engine/clusterclaims-controller-rhel9:1787259059. Affected products named by the advisory: multicluster engine for Kubernetes 2.10; multicluster engine for Kubernetes 2.11; multicluster engine for Kubernetes 2.17; multicluster engine for Kubernetes 2.6; and 2 more. Affected products named by the advisory: multicluster engine for Kubernetes 2.8; multicluster engine for Kubernetes 2.9.

CVE-2026-73267
Unclassified
Aug 11, 2026
High7.4Red Hat

High [CVE-2026-66806] TLS verification disabled when sending hub pull-secret to console.redhat.com

TLS verification disabled when sending hub pull-secret to console.redhat.com. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:59579 with package multicluster-engine/console-mce-rhel9:1787264250, rhacm2/console-rhel9:1787687062. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66806
Unclassified
Aug 10, 2026
High7.8Red Hat

High [CVE-2026-72913] Arbitrary Code Execution via Chained DCS Escape Sequences

Arbitrary Code Execution via Chained DCS Escape Sequences. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: External Secrets Operator for Red Hat OpenShift; Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gvisor-tap-vsock.

CVE-2026-72913
Red Hat Enterprise Linux
Aug 10, 2026
High7.8Red Hat

High [CVE-2026-63622] swtpm privilege escalation via symlink following

swtpm privilege escalation via symlink following. Red Hat rates this important (CVSS 7.8). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: libvirt.

CVE-2026-63622
Red Hat Enterprise Linux
Aug 10, 2026
High8.8Vendor: CriticalRed Hat

High [CVE-2026-18982] RHOAI fork aggregates training job create onto native edit/admin ClusterRoles

RHOAI fork aggregates training job create onto native edit/admin ClusterRoles. Red Hat rates this critical (CVSS 8.8). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-training-operator-rhel9:1787361677, rhoai/odh-training-operator-rhel9:1784814352, rhoai/odh-training-operator-rhel9:1785187053, rhoai/odh-training-operator-rhel9:1785188461. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.

CVE-2026-18982
Unclassified
Aug 10, 2026
High8.8Vendor: CriticalRed Hat

High [CVE-2026-18951] [Trainer v2 Security] TRN-02: RHOAI overlay aggregates trainjobs CRUD into standard edit ClusterRole

[Trainer v2 Security] TRN-02: RHOAI overlay aggregates trainjobs CRUD into standard edit ClusterRole. Red Hat rates this critical (CVSS 8.8). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-training-operator-rhel9:1787361677, rhoai/odh-training-operator-rhel9:1784814352, rhoai/odh-training-operator-rhel9:1785188461. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.

CVE-2026-18951
Unclassified
Aug 10, 2026
High8.8Vendor: CriticalRed Hat

High [CVE-2026-18950] Confused-deputy privilege escalation via unchecked roleRef in RoleBinding creation

Confused-deputy privilege escalation via unchecked roleRef in RoleBinding creation. Red Hat rates this critical (CVSS 8.8). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-dashboard-rhel9:1786109665, rhoai/odh-dashboard-rhel9:1785940823, rhoai/odh-dashboard-rhel9:1786109683. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.

CVE-2026-18950
Unclassified
Aug 10, 2026
High8.8Vendor: CriticalRed Hat

High [CVE-2026-18949] ClusterRole grants cluster-wide CRUD on secrets and RBAC management resources

ClusterRole grants cluster-wide CRUD on secrets and RBAC management resources. Red Hat rates this critical (CVSS 8.8). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-dashboard-rhel9:1786109665, rhoai/odh-dashboard-rhel9:1785940823, rhoai/odh-dashboard-rhel9:1786109683. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI (RHOAI).

CVE-2026-18949
Unclassified
Aug 10, 2026
High8.5Red Hat

High [CVE-2026-18947] Authorization bypass in /materialize endpoints enables DoS via unauthorized full re-materialization

Authorization bypass in /materialize endpoints enables DoS via unauthorized full re-materialization. Red Hat rates this important (CVSS 8.5). Red Hat lists fixing advisory RHSA-2026:53263 with package rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786110033. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3.

CVE-2026-18947
Unclassified
Aug 10, 2026
High7.7Red Hat

High [CVE-2026-18941] Default authentication mode is no_auth — shared multi-tenant instances deployed without authentication

Default authentication mode is no_auth — shared multi-tenant instances deployed without authentication. Red Hat rates this important (CVSS 7.7). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786110033, rhoai/odh-feature-server-rhel9:1786107278. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.4.

CVE-2026-18941
Unclassified
Aug 10, 2026
High8.0Red Hat

High [CVE-2026-15581] TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide

TAS internal Service bypasses kube-rbac-proxy, exposing unauthenticated Quarkus API cluster-wide. Red Hat rates this important (CVSS 8). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-trustyai-service-operator-rhel9:1784993206, rhoai/odh-trustyai-service-operator-rhel9:1786614608, rhoai/odh-trustyai-service-operator-rhel9:1785187521, rhoai/odh-trustyai-service-operator-rhel9:1785187119. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.

CVE-2026-15581
Unclassified
Aug 10, 2026
High8.1Red Hat

High [CVE-2026-15467] LMEvalJob sidecar containers bypass protected environment variable filtering, allowing TRUST_REMOTE_CODE policy override

LMEvalJob sidecar containers bypass protected environment variable filtering, allowing TRUST_REMOTE_CODE policy override. Red Hat rates this important (CVSS 8.1). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-trustyai-service-operator-rhel9:1784993206, rhoai/odh-trustyai-service-operator-rhel9:1786614608, rhoai/odh-trustyai-service-operator-rhel9:1785187521, rhoai/odh-trustyai-service-operator-rhel9:1785187119. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.

CVE-2026-15467
Unclassified
Aug 10, 2026
High8.8Red Hat

High [CVE-2026-13717] MaaS/llm-d inference Gateway: default allowedRoutes.namespaces.from: All allows namespace users to hijack shared model-serving traffic (tokens, prompts, outputs)

MaaS/llm-d inference Gateway: default allowedRoutes.namespaces.from: All allows namespace users to hijack shared model-serving traffic (tokens, prompts, outputs). Red Hat rates this important (CVSS 8.8). Weakness: CWE-284. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-rhel9-operator:1786123541, rhoai/odh-maas-controller-rhel9:1787153684. Affected products named by the advisory: Red Hat OpenShift AI 3.4; Red Hat OpenShift AI (RHOAI).

CVE-2026-13717
Unclassified
Aug 10, 2026
High8.0Red Hat

High [CVE-2026-66805] stored DOM XSS via unescaped pod logs in document.write

stored DOM XSS via unescaped pod logs in document.write. Red Hat rates this important (CVSS 8). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:54432 with package multicluster-engine/console-mce-rhel9:1787079359, rhacm2/console-rhel9:1787339248, multicluster-engine/console-mce-rhel9:1787264250, rhacm2/console-rhel9:1787339213.

CVE-2026-66805
Unclassified
Aug 10, 2026
High7.1Red Hat

High [CVE-2026-69112] Path Traversal and Denial of Service via weight_map

Path Traversal and Denial of Service via weight_map. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22. Affected products named by the advisory: Lightspeed Core; OpenShift Lightspeed; Red Hat AI Inference Server; Red Hat Enterprise Linux AI (RHEL AI) 3; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-69112
Unclassified
Aug 10, 2026
High7.6Red Hat

High [CVE-2026-18621] V1 Argo template path accepts arbitrary Workflow spec, bypassing all v2 security hardening

V1 Argo template path accepts arbitrary Workflow spec, bypassing all v2 security hardening. Red Hat rates this important (CVSS 7.6). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-ml-pipelines-api-server-v2-rhel9:1784924951, rhoai/odh-ml-pipelines-api-server-v2-rhel9:1787173417, rhoai/odh-ml-pipelines-api-server-v2-rhel9:1785189934, rhoai/odh-ml-pipelines-api-server-v2-rhel9:1785187920. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.

CVE-2026-18621
Unclassified
Aug 10, 2026
High7.1Vendor: MediumRed Hat

High [CVE-2026-18620] User-controlled ServiceAccount for workflow pods without authorization check — confused deputy

User-controlled ServiceAccount for workflow pods without authorization check — confused deputy. Red Hat rates this moderate (CVSS 7.1). Weakness: CWE-639. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-ml-pipelines-api-server-v2-rhel9:1784924951, rhoai/odh-ml-pipelines-api-server-v2-rhel9:1787173417, rhoai/odh-ml-pipelines-api-server-v2-rhel9:1785189934, rhoai/odh-ml-pipelines-api-server-v2-rhel9:1785187920. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.

CVE-2026-18620
Unclassified
Aug 10, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-18618] Bundled gRPC 1.46.3 (2022) with published HTTP/2 DoS CVEs — directly reachable on listener

Bundled gRPC 1.46.3 (2022) with published HTTP/2 DoS CVEs — directly reachable on listener. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-mlmd-grpc-server-rhel9:1785260280, rhoai/odh-mlmd-grpc-server-rhel9:1785262015, rhoai/odh-mlmd-grpc-server-rhel9:1785269945. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.4.

CVE-2026-18618
Unclassified
Aug 10, 2026