Complete feed
Action required
Critical/high still unreviewed, or CISA KEV listed
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-65819] Remote Denial of Service via crafted packet processing
Remote Denial of Service via crafted packet processing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-805.
High [CVE-2026-19015] Uncontrolled resource consumption leading to denial of service
Uncontrolled resource consumption leading to denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-71556] Arbitrary file read/write via symbolic link resolution
Arbitrary file read/write via symbolic link resolution. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-20337 +6] ClamAV Vulnerabilities Affecting Cisco Products: August 2026
Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For additional information on these vulnerabilities in ClamAV, see the ClamAV blog. Cisco has released software updates that address these vulnerabilities in affected Cisco platforms. There are no workarounds that address these vulnerabilities. Notes: - The Security Impact Rating (SIR) for these vulnerabilities is High for Windows-based platforms only because those platforms run the ClamAV scanning process in a privileged security context. The platforms that are highly impacted include Cisco Secure Endpoint Connector for Windows. - The SIR for these vulnerabilities is Medium on other platforms, including Linux and Mac platforms, because those platforms run the ClamAV scanning process in a lower-privileged security context. The affected platforms include Secure Endpoint Connector for Linux and Mac. - Cisco Secure Endpoint Private Cloud itself is not impacted by these vulnerabilities. However, the Cisco Secure Endpoint Connector software that is distributed from the device is impacted.
High [CVE-2026-15816] root code execution via unescaped error message written to sourced emergency hook script in die
root code execution via unescaped error message written to sourced emergency hook script in die(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:54575 with package dracut-0:057-54.git20250423.el9_4.3, dracut-0:057-25.git20250717.el9_2.2, dracut-0:057-89.git20250311.el9_6.1, dracut-0:105-4.el10_0.1. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions; Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions; and 4 more.
High [CVE-2026-71559] Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic
Deserialization of Untrusted Data vulnerability in the Go implementation of Apache Fory allows an attacker to cause a denial of service by supplying crafted data containing malformed type metadata, which triggers an uncaught panic. This issue affects Apache Fory: from 0.16.0 before 1.5.0. Users of other language implementations are not affected. Users are recommended to upgrade to version 1.5.0, which fixes the issue.
High [CVE-2025-63235] codepr sol: Sol: Denial of service via resource exhaustion from malformed CONNECT packets
codepr sol: Sol: Denial of service via resource exhaustion from malformed CONNECT packets. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772.
High [CVE-2026-66035] Libssh2 Vulnerability in NetApp Products
Libssh2 versions through 1.11.1 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-64531] Linux Kernel Vulnerability in NetApp Products
Certain Linux kernel versions are susceptible to a vulnerability referred to as OVSwrap which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
High [CVE-2026-66033] Libssh2 Vulnerability in NetApp Products
Libssh2 versions through 1.11.1 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). Affected products: Active IQ Unified Manager for VMware vSphere, ONTAP Select Deploy administration utility. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Critical [CVE-2026-18367] privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6
A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6.
Critical [CVE-2026-19173] Sandbox escape via out-of-bounds write in Chromium
Sandbox escape via out-of-bounds write in Chromium. Red Hat rates this important (CVSS 9). Weakness: CWE-787.
Critical [CVE-2026-19155] Sandbox escape via use-after-free in Payments
Sandbox escape via use-after-free in Payments. Red Hat rates this important (CVSS 9). Weakness: CWE-825.
Critical [CVE-2026-19137] Google Chrome on Android: Sandbox escape via use after free in WebGL
Google Chrome on Android: Sandbox escape via use after free in WebGL. Red Hat rates this important (CVSS 9). Weakness: CWE-825.
Critical [CVE-2026-71476] @nx/s3-cache: @nx/gcs-cache: @nx/azure-cache: @nx/shared-fs-cache: @nx/powerpack-s3-cache: @nx/powerpack-gcs-cache: @nx/powerpack-azure-cache: @nx/powerpack-shared-fs-cache: Nx: Remote Code Executi…
@nx/s3-cache: @nx/gcs-cache: @nx/azure-cache: @nx/shared-fs-cache: @nx/powerpack-s3-cache: @nx/powerpack-gcs-cache: @nx/powerpack-azure-cache: @nx/powerpack-shared-fs-cache: Nx: Remote Code Execution via Zip-Slip vulnerability in self-hosted remote cache. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-22. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.
Critical [CVE-2026-32327] bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem function
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Critical [CVE-2026-34191] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3
Critical [CVE-2026-5134] Loca Software Informatics Technology Ltd. Co. CMS: CMS: Critical SQL Injection vulnerability
Loca Software Informatics Technology Ltd. Co. CMS: CMS: Critical SQL Injection vulnerability. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-89.
Critical [CVE-2026-61466] In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist
In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client registration request verbatim, without validating it against an AS-defined allowlist. This could lead to a client self-assigning privileged scopes at registration time. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Critical [CVE-2026-63687] Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters
Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute the code_challenge, code_challenge_method, nonce, and state values that were set in the outer HTTP request, undermining PKCE integrity and OpenID Connect replay protection. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.