Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-6368] Process abort due to invalid memory in wordexp
Process abort due to invalid memory in wordexp. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1341. Red Hat lists fixing advisory RHSA-2026:53069 with package glibc-main-2.43-8.1.hum1. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: glibc; and 1 more.
Medium [CVE-2026-68872] The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed
The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with either backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using one of these backends. Users are advised to upgrade to apache-airflow-providers-amazon 9.34.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace.
Medium [CVE-2026-68871] The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed
The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-yandex 4.5.1 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace.
Medium [CVE-2026-68870] The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed
The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Variable id through the team-agnostic lookup when the team-scoped lookup missed. In a deployment running multi-team mode with this backend, a caller in one team could resolve a secret belonging to another team by supplying an id that spells out that team's namespace, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-microsoft-azure 14.1.0 or later, which refuses the team-agnostic fall-through for an id that could name a team namespace.
Medium [CVE-2026-63623] Information disclosure via world-readable storage volume images during clone/convert
Information disclosure via world-readable storage volume images during clone/convert. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-732.
Medium [CVE-2026-71577] Spec-topic Read ACL leaks bootstrap kubeconfigs to all managed hubs during migration
Spec-topic Read ACL leaks bootstrap kubeconfigs to all managed hubs during migration. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-522.
Medium [CVE-2026-6373] Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allows Web Application Fingerprinting
Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allows Web Application Fingerprinting. This issue affects WAH7601: through 20072026.
Medium [CVE-2026-15060] Unprivileged users can terminate arbitrary processes
Unprivileged users can terminate arbitrary processes. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-266.
Medium [CVE-2026-18370] Heap-based buffer overflow leads to denial of service
Heap-based buffer overflow leads to denial of service. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.
Medium [CVE-2026-19278] Privilege escalation via unanchored regular expressions in Auth M2M role mappings
Privilege escalation via unanchored regular expressions in Auth M2M role mappings. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-625.
Medium [CVE-2026-19429] Arbitrary file read via symlink target validation bypass
Arbitrary file read via symlink target validation bypass. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-59. Affected product named by the advisory: OpenShift Developer Tools and Services.
Medium [CVE-2026-68428] Fix use-after-free on vendor module reload
Fix use-after-free on vendor module reload. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-68425] Drop unmatched RMPP responses before reassembly
Drop unmatched RMPP responses before reassembly. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-179. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-68424] fix use-after-free in mtd_virt_concat_destroy_joins
fix use-after-free in mtd_virt_concat_destroy_joins(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-68423] fix use-after-free in mtd_virt_concat_destroy
fix use-after-free in mtd_virt_concat_destroy(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825.
Medium [CVE-2026-68422] fix root leak if its reloc root is unexpected in merge_reloc_roots
fix root leak if its reloc root is unexpected in merge_reloc_roots(). Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-68421] Don't warn on core-sched forced idle in put_prev_task_scx
Don't warn on core-sched forced idle in put_prev_task_scx(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1288. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.
Medium [CVE-2026-68418] Prevent user-triggered null deref on QP create
Prevent user-triggered null deref on QP create. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel-rt.
Medium [CVE-2026-68417] publish QP after initialization
publish QP after initialization. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-908. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-68413] memory leak in ipw2100_pci_init_one
memory leak in ipw2100_pci_init_one(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.