Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.5Apache

High [CVE-2026-55814] Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0

Missing Authentication in Apache Ranger Download APIs on versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

CVE-2026-55814
Unclassified
Aug 10, 2026
High7.5Apache

High [CVE-2026-65942] TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0

TLS hostname verification issue in Apache Ranger Client Code in versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

CVE-2026-65942
Unclassified
Aug 10, 2026
High7.3Apache

High [CVE-2026-65948] UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0

UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0. Note: UnixAuth is NOT a recommended option for production deployments. Users are recommended to upgrade to version 2.9.0, which fixes this issue.

CVE-2026-65948
Unclassified
Aug 10, 2026
High7.5Apache

High [CVE-2026-44630] Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to cause a denial of service

Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to cause a denial of service. By sending a crafted malformed Thrift frame, an attacker can cause IoTDB to allocate an excessive amount of memory and crash with an OutOfMemoryError. This issue affects Apache IoTDB: before 1.3.8, from 2.0.0 before 2.0.9. Users are recommended to upgrade to version 2.0.10, which fixes the issue.

CVE-2026-44630
Unclassified
Aug 10, 2026
High7.1Red Hat

High [CVE-2026-19389] integer overflow/underflow in asfdemux bounds checks leading to out-of-bounds read

integer overflow/underflow in asfdemux bounds checks leading to out-of-bounds read. Red Hat rates this important (CVSS 7.1). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:55865 with package gstreamer1-plugins-bad-free-0:1.22.12-7.el9_8.4, gstreamer1-plugins-ugly-free-0:1.22.12-6.el9_8.2, gstreamer1-plugins-ugly-free-0:1.26.7-2.el10_2.2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-19389
Unclassified
Aug 10, 2026
High7.6Red Hat

High [CVE-2026-19387] heap out-of-bounds write in adpcmdec IMA/DVI ADPCM decoder

heap out-of-bounds write in adpcmdec IMA/DVI ADPCM decoder. Red Hat rates this important (CVSS 7.6). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:55865 with package gstreamer1-plugins-bad-free-0:1.26.7-2.el10_2.7, gstreamer1-plugins-bad-free-0:1.22.12-7.el9_8.4, gstreamer1-plugins-ugly-free-0:1.22.12-6.el9_8.2, gstreamer1-plugins-bad-free-0:1.16.1-9.el8_10.2. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-19387
Unclassified
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68388] handle overlapping allocated ranges in fallocate

handle overlapping allocated ranges in fallocate. Red Hat rates this moderate (CVSS 7). Weakness: CWE-131. Red Hat lists fixing advisory RHSA-2026:57251 with package kernel-0:6.12.0-211.49.1.el10_2, kernel-0:5.14.0-687.41.1.el9_8, kernel-rt-0:4.18.0-553.157.1.rt7.498.el8_10, kernel-0:4.18.0-553.157.1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-68388
Unclassified
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68315] validate stream count in sctp_process_strreset_inreq

validate stream count in sctp_process_strreset_inreq(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68315
Linux Kernel
Aug 10, 2026
High7.3Red Hat

High [CVE-2026-68426] fix stale skb->prev after async crypto steals a GSO segment

fix stale skb->prev after async crypto steals a GSO segment. Red Hat rates this important (CVSS 7.3). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68426
Linux Kernel
Aug 10, 2026
High7.3Red Hat

High [CVE-2026-68201] drain a slave's callback before its master detaches it

drain a slave's callback before its master detaches it. Red Hat rates this important (CVSS 7.3). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68201
Linux Kernel
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68086] write all dirty file folios when collapsing

write all dirty file folios when collapsing. Red Hat rates this moderate (CVSS 7). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68086
Linux Kernel
Aug 10, 2026
High7.0Red Hat

High [CVE-2026-68236] set new_stream to NULL after release

set new_stream to NULL after release. Red Hat rates this important (CVSS 7). Weakness: CWE-763. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68236
Linux Kernel
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68293] Fix MCIA register buffer overflow on 32 dword reads

Fix MCIA register buffer overflow on 32 dword reads. Red Hat rates this moderate (CVSS 7). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.

CVE-2026-68293
Linux Kernel
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68390] hold hdev->lock for hci_conn_params lookups

hold hdev->lock for hci_conn_params lookups. Red Hat rates this moderate (CVSS 7). Weakness: CWE-414. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.

CVE-2026-68390
Linux Kernel
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68400] Fix Endpoint Memory Access Descriptor offset calculation

Fix Endpoint Memory Access Descriptor offset calculation. Red Hat rates this moderate (CVSS 7). Weakness: CWE-823. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.

CVE-2026-68400
Linux Kernel
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68117] clear sock->sk on the failed-insert path in tipc_sk_create

clear sock->sk on the failed-insert path in tipc_sk_create(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68117
Linux Kernel
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68147] Avoid dynamic allocation in fscrypt_get_devices

Avoid dynamic allocation in fscrypt_get_devices(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-825.

CVE-2026-68147
Unclassified
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68300] verify auth requirement when auth_chunk is NULL

verify auth requirement when auth_chunk is NULL. Red Hat rates this moderate (CVSS 7). Weakness: CWE-303. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-68300
Linux Kernel
Aug 10, 2026
High7.8Red Hat

High [CVE-2026-68380] Fix use-after-free of mm_struct in job scheduler

Fix use-after-free of mm_struct in job scheduler. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825.

CVE-2026-68380
Unclassified
Aug 10, 2026
High7.0Vendor: MediumRed Hat

High [CVE-2026-68267] Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists

Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists. Red Hat rates this moderate (CVSS 7). Weakness: CWE-1188. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel-rt.

CVE-2026-68267
Linux Kernel
Aug 10, 2026