Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-11814] command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs. Affected products named by the advisory: BE9300; MR60; MS60; R6700AX; and 4 more. Affected products named by the advisory: RAX10; RAX120; RAX120v2; RAX20.
Medium [CVE-2026-71193] cross-tenant DNS zone overlap via pool-scoped ownership checks when using AttributeFilter scheduler
cross-tenant DNS zone overlap via pool-scoped ownership checks when using AttributeFilter scheduler. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-863. Affected products named by the advisory: Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-71194] mDNS NOTIFY handler DoS via pool-blind zone lookup
mDNS NOTIFY handler DoS via pool-blind zone lookup. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-863. Affected products named by the advisory: Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-73067] Denial of Service due to crafted data model
Denial of Service due to crafted data model. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-72745] Information disclosure and memory corruption via malformed Kerberos GSS Wrap token
Information disclosure and memory corruption via malformed Kerberos GSS Wrap token. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-823. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.
Medium [CVE-2026-33922] Arbitrary file deletion via path traversal in Offline archives functionality
Arbitrary file deletion via path traversal in Offline archives functionality. Red Hat rates this moderate (CVSS 6). Weakness: CWE-22.
Medium [CVE-2026-33921] Information disclosure and arbitrary packet sending via insecure access restrictions
Information disclosure and arbitrary packet sending via insecure access restrictions. Red Hat rates this moderate (CVSS 5.2). Weakness: CWE-1188.
Medium [CVE-2026-71218] Unbounded peer-controlled allocation in iperf3 JSON_read allows unauthenticated remote memory exhaustion
Unbounded peer-controlled allocation in iperf3 JSON_read() allows unauthenticated remote memory exhaustion. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-789. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-19519] denial of service via unchecked type assertion in RPM header parser
denial of service via unchecked type assertion in RPM header parser. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-617. Affected products named by the advisory: Red Hat Advanced Cluster Security 4; Red Hat Quay 3.
Medium [CVE-2026-6727] MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability
MITRE: CVE-2026-6727 TPM 2.0 RSA OAEP Timing Side-Channel Vulnerability Affected products named by the advisory: Windows Server 2019; Windows Server 2022; Windows Server 2025.
Medium [CVE-2026-19391] Incomplete credential redaction exposes SSSD bind passwords and Pacemaker fence credentials in uploaded archives
Incomplete credential redaction exposes SSSD bind passwords and Pacemaker fence credentials in uploaded archives. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-312. Affected products named by the advisory: Pen Drive Powered by Red Hat Lightspeed; Red Hat Certification Program for Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat package: insights-core.
Medium [CVE-2026-5304] Privilege escalation via malicious ACAP application installation
Privilege escalation via malicious ACAP application installation. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: axis.
Medium [CVE-2026-24330] Arbitrary File Read via malicious archive deployment
Arbitrary File Read via malicious archive deployment. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-434. Affected products named by the advisory: Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 2 more. Affected products named by the advisory: Red Hat Process Automation 7; Red Hat Single Sign-On 7.
Medium [CVE-2026-24329] Denial of Service via malformed payload injection by an authenticated administrative user.
Denial of Service via malformed payload injection by an authenticated administrative user. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-91. Affected products named by the advisory: Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 2 more. Affected products named by the advisory: Red Hat Process Automation 7; Red Hat Single Sign-On 7.
Medium [CVE-2026-62899] .NET:.NET Core:.NET Security Feature Bypass Vulnerability
.NET:.NET Core:.NET Security Feature Bypass Vulnerability. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:54542 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet8.0-0:8.0.130-1.el8_10, dotnet9.0-0:9.0.120-1.el9_6, dotnet10.0-0:10.0.111-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
Medium [CVE-2026-62900] .NET:.NET Information Disclosure Vulnerability
.NET:.NET Information Disclosure Vulnerability. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-212. Red Hat lists fixing advisory RHSA-2026:54542 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet8.0-0:8.0.130-1.el8_10, dotnet9.0-0:9.0.120-1.el9_6, dotnet10.0-0:10.0.111-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
Medium [CVE-2026-6426] vhost inflight migration VMState integer type mismatch causes out-of-bounds access
vhost inflight migration VMState integer type mismatch causes out-of-bounds access. Red Hat rates this low (CVSS 4.4). Weakness: CWE-681. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-18942] feast apply CronJob runs user Python with feature-server SA — tenant code to SA token escalation
feast apply CronJob runs user Python with feature-server SA — tenant code to SA token escalation. Red Hat rates this important (CVSS 5.5). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786107278. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.4.
Medium [CVE-2026-16456] Cross-namespace secret read via NIM Account CRD confused deputy
Cross-namespace secret read via NIM Account CRD confused deputy. Red Hat rates this important (CVSS 6.5). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-model-controller-rhel9:1785187158, rhoai/odh-model-controller-rhel9:1784950479, rhoai/odh-model-controller-rhel9:1785189333. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.4.
Medium [CVE-2026-6791] Denial of Service via stack exhaustion during tilde expansion
Denial of Service via stack exhaustion during tilde expansion. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:53069 with package glibc-main-2.43-8.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: glibc; and 1 more.