Complete feed
Action required
Critical/high still unreviewed, or CISA KEV listed
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-68074] Apache Qpid Broker-J: pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fixes the issue.
High [CVE-2026-66257] Denial of Service via unbounded symbol value caching
Denial of Service via unbounded symbol value caching. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-66257] Apache Qpid Proton-J: pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Proton-J: through 0.34.1. Users are recommended to upgrade to version 0.35.0, which fixes the issue.
High [CVE-2026-64572] free fib_alias with kfree_rcu on insert error path
free fib_alias with kfree_rcu() on insert error path. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-67863] Denial of Service via use-after-free vulnerability
Denial of Service via use-after-free vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825.
High [CVE-2026-67870] Denial of Service via incomplete validation in AddReferences
Denial of Service via incomplete validation in AddReferences. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476.
High [CVE-2026-67869] Denial of Service via buffer overflow in Service_Call
Denial of Service via buffer overflow in Service_Call. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125.
High [CVE-2026-64577] check skb_pull_data return in gtp1u_send_echo_resp
check skb_pull_data() return in gtp1u_send_echo_resp(). Red Hat rates this moderate (CVSS 7). Weakness: CWE-124.
High [CVE-2026-64573] fix NVM tag length underflow in TLV parser
fix NVM tag length underflow in TLV parser. Red Hat rates this moderate (CVSS 7). Weakness: CWE-125.
High [CVE-2026-64582] Fix a use-after-free problem in rxe_mmap
Fix a use-after-free problem in rxe_mmap. Red Hat rates this important (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-67864] Denial of Service via NodeManagement type-instantiation logic
Denial of Service via NodeManagement type-instantiation logic. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1287.
Critical [CVE-2026-63456] Authentication bypass via spoofed HTTP headers Orchestrator REST API
Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system functions. Successful exploitation could allow an attacker to view and modify potentially sensitive information on the target system. Affected product named by the advisory: EdgeConnect SD-WAN Orchestrator.
Critical [CVE-2026-58067 +3] Vulnerabilities Resolved in Veeam Service Provider Console 9.3
Vulnerabilities Resolved in Veeam Service Provider Console 9.3 KB ID: 4893 Product: Published: 2026-08-04 Last Modified: Veeam Software Security Commitment Veeam® is committed to ensuring its products protect customers from potential risks. As part of that commitment, we operate a Vulnerability Disclosure Program (VDP) for all Veeam products and perform extensive internal code audits. When a vulnerability is identified, our team promptly develops a patch to address and mitigate the risk. In line with our dedication to transparency, we publicly disclose the vulnerability and provide detailed mitigation information. This approach ensures that all potentially affected customers can quickly implement the necessary measures to safeguard their systems. It’s important to note that once a vulnerability and its associated patch are disclosed, attackers will likely attempt to reverse-engineer the patch to exploit unpatched deployments of Veeam software. This reality underscores the critical importance of ensuring that all customers use the latest versions of our software and install all updates and patches without delay. Issue Details A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent and obtain that agent's credentials. Severity: Critical
High [CVE-2026-56848] Heap-use-after-free in HTTP/2 handling can lead to denial of service
Heap-use-after-free in HTTP/2 handling can lead to denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-15307] Remote code execution via GeoDjango spatial lookups
Remote code execution via GeoDjango spatial lookups. Red Hat rates this important (CVSS 8.8). Weakness: CWE-434. Red Hat lists fixing advisory RHSA-2026:59153 with package ansible-automation-platform-25/hub-rhel8:1787101922, ansible-automation-platform-26/lightspeed-rhel9:1787244079, python3.12-django-0:5.2.17-1.el8ap, ansible-automation-platform-25/lightspeed-rhel8:1787229385. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Discovery 2; Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 5 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0; Red Hat Satellite 6; Red Hat Update Infrastructure 4 for Cloud Providers; Red Hat Update Infrastructure 5; and 1 more.
High [CVE-2026-68494] Denial of Service via incomplete fix in async JSON parser
Denial of Service via incomplete fix in async JSON parser. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:53643 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, jackson-core. Affected products named by the advisory: Cryostat 4; OpenShift Developer Tools and Services; OpenShift Serverless; Red Hat AI Inference Server; and 28 more. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat AMQ Clients; Red Hat Ansible Automation Platform 2; Red Hat build of Apache Camel 4 for Quarkus 3; and 24 more.
High [CVE-2026-42169] GIMP APNG loader heap-buffer-overflow when fcTL width exceeds IHDR width (file-png.c)
GIMP APNG loader heap-buffer-overflow when fcTL width exceeds IHDR width (file-png.c). Red Hat rates this moderate (CVSS 7.3). Weakness: CWE-131. Red Hat lists fixing advisory RHSA-2026:50817 with package gimp-2:3.0.4-4.el9_8.9. Affected product named by the advisory: Red Hat Enterprise Linux 9.
High [CVE-2026-14818] path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN series firmware versions from V4.16 through V5.42 Patch 1 could allow an authenticated attacker with administrator privileges to execute a crafted malicious configuration file on an affected device
A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 Patch 1, USG FLEX series firmware versions from V4.50 through V5.42 Patch 1, USG FLEX 50(W) series firmware versions from V4.16 through V5.42 Patch 1, and USG20(W)-VPN series firmware versions from V4.16 through V5.42 Patch 1 could allow an authenticated attacker with administrator privileges to execute a crafted malicious configuration file on an affected device.
High [CVE-2026-6837] post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device
A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.
High [CVE-2026-56846] Remote memory exhaustion via HTTP/2 retained header blocks
Remote memory exhaustion via HTTP/2 retained header blocks. Red Hat rates this important (CVSS 7.5). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:48305 with package nodejs22-main-22.23.2-2.3.hum1, nodejs24-main-24.18.1-0.1.hum1.