Complete feed
Action required
Critical/high still unreviewed, or CISA KEV listed
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-63687] Security bypass due to improper handling of authorization parameters
Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensitive parameters. A client that can produce a validly-signed request JWT (e.g., one whose client_secret is known or compromised) can thereby substitute the code_challenge, code_challenge_method, nonce, and state values that were set in the outer HTTP request, undermining PKCE integrity and OpenID Connect replay protection. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue. This vulnerability allows an attacker, who has compromised a client's secret, to bypass critical security protections in the authorization process. By injecting malicious values for parameters like code_challenge and nonce, the attacker can undermine the integrity of Proof Key for Code Exchange (PKCE) and OpenID Connect replay protection, potentially leading to unauthorized access or session hijacking. This could lead to unauthorized access or session hijacking in applications utilizing affected Red Hat middleware products that rely on these security mechanisms. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N). Weakness: CWE-807.
High [CVE-2026-68481] In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true
In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:true. The same applies to refresh tokens. This violates the RFC stipulations that 'The authorization server MUST invalidate the token.' and 'introspection of a revoked token MUST return {"active":false}'. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
High [CVE-2026-65432] Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities
Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any or referenced from that top-level WSDL is handed off to WSDL4J, which does not disable DOCTYPE declarations or external entities. As a result, the protections applied to the top-level document do not extend to imported documents, leaving imported WSDL/XSD content vulnerable to XML External Entity (XXE) attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
High [CVE-2026-57817] Apache CXF RP: The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow
The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache CXF RP is integrated with a non-compliant or misconfigured Identity Provider (IdP) that omits the `c_hash`, the RP becomes vulnerable to Authorization Code Substitution/Injection attacks. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
High [CVE-2026-66909] Remote Code Execution via unsafe deserialization of JMS ObjectMessage
Remote Code Execution via unsafe deserialization of JMS ObjectMessage. Red Hat rates this important (CVSS 8.1). Weakness: CWE-502. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 1 more. Affected products named by the advisory: Red Hat Single Sign-On 7.
High [CVE-2026-50645 +1] incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers
An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with many attachment headers. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
High [CVE-2026-57819] Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option
Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, no default limit is set which may lead to denial of service attacks when processing requests with very large numbers of form parameters. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue by using a default limit of 500 parameters.
High [CVE-2026-54225] Apache CXF allows to control the maximum attachment size via the "attachment-max-size"
Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no default placed on this size, meaning that a denial of service attack is possible if the user doesn't explicitly set the limit. Users should update to Apache CXF 4.2.3 or 4.1.8 or 3.6.12 which fixes this problem by imposing a default attachment size limit of 50mb.
High [CVE-2026-18649] unbounded memory growth in rtph264depay and rtph265depay RTP depayloaders
unbounded memory growth in rtph264depay and rtph265depay RTP depayloaders. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:53451 with package gstreamer1-plugins-good-0:1.26.7-2.el10_2.3, gstreamer1-plugins-good-0:1.22.12-7.el9_8.2, gstreamer1-plugins-good-0:1.16.1-7.el8_10.3. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8. Affected products named by the advisory: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions; Red Hat Enterprise Linux 7.
High [CVE-2026-64597] fix double-free in SMB2_close replay
fix double-free in SMB2_close() replay. Red Hat rates this important (CVSS 7). Weakness: CWE-415. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel-rt.
Critical [CVE-2026-20267 +6] Cisco IOS XE Software Security Hardening Release: August 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class ��� Common Weakness Enumeration (CWE) ��� and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
Critical [CVE-2026-20303 +4] Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. Affected products named by the advisory: Catalyst SD-WAN Controller; Catalyst SD-WAN Manager.
Critical [CVE-2026-60053] Insufficient Session Expiration vulnerability in Apache Answer
Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained usable after the owning administrator was demoted or the account was marked inactive, suspended, or deleted, allowing continued access until the keys were explicitly removed. Users are recommended to upgrade to version 2.0.2, which fixes the issue.
Critical [CVE-2026-10090] namespace edit user can deploy cluster-scoped ClusterRoleBinding and become cluster-admin via Application Subscription
namespace edit user can deploy cluster-scoped ClusterRoleBinding and become cluster-admin via Application Subscription. Red Hat rates this important (CVSS 9). Weakness: CWE-267. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.17; Red Hat Advanced Cluster Management for Kubernetes 2.11; and 2 more.
Critical [CVE-2026-10059] namespace admin can escalate to cluster-wide curator authority via ClusterCurator ServiceAccount token
namespace admin can escalate to cluster-wide curator authority via ClusterCurator ServiceAccount token. Red Hat rates this important (CVSS 9.1). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:59557 with package multicluster-engine/cluster-curator-controller-rhel9:1787238383, multicluster-engine/cluster-curator-controller-rhel9:1787264185, multicluster-engine/cluster-curator-controller-rhel9:1787259011, multicluster-engine/cluster-curator-controller-rhel9:1787201612. Affected product named by the advisory: Multicluster Engine for Kubernetes.
Critical [CVE-2026-61486] ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy
- * UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Critical [CVE-2026-61484] ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy
- * UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
High [CVE-2026-71312] Server-Side Command Execution via Malicious SFTP Filenames
Server-Side Command Execution via Malicious SFTP Filenames. Red Hat rates this important (CVSS 8). Weakness: CWE-78.
High [CVE-2026-34966] Information disclosure via Server-Side Request Forgery (SSRF) bypass
Information disclosure via Server-Side Request Forgery (SSRF) bypass. Red Hat rates this important (CVSS 7.6). Weakness: CWE-918.
High [CVE-2026-71309] Backend Root Escape via Incomplete Path Validation
Backend Root Escape via Incomplete Path Validation. Red Hat rates this important (CVSS 8.1). Weakness: CWE-22.