Complete feed
Security advisories & CVEs
1780 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-21399] Intel Open Volume Kernel Library: Intel Open Volume Kernel Library: Denial of Service via heap-based buffer overflow
Intel Open Volume Kernel Library: Intel Open Volume Kernel Library: Denial of Service via heap-based buffer overflow. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-120.
Medium [CVE-2026-20908] Intel NPU Driver for Windows: Denial of Service via time-of-check time-of-use race condition
Intel NPU Driver for Windows: Denial of Service via time-of-check time-of-use race condition. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-367.
Medium [CVE-2026-20786] Denial of service via out-of-bounds read
Out-of-bounds read for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. This vulnerability, an out-of-bounds read, could allow a local attacker with low privileges to cause a denial of service (DoS). A denial of service means the system or application becomes unavailable to legitimate users. The flaw can be exploited by an unprivileged, authenticated user through local access without requiring user interaction or special knowledge. Successful exploitation primarily impacts the availability of the system, making it unresponsive or unusable. Red Hat products are not affected by this vulnerability as they do not ship the Intel NPU Driver. Community packages in Fedora and EPEL are tracked separately. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H). Weakness: CWE-125.
Medium [CVE-2026-20783] Denial of Service via improper conditions check
Denial of Service via improper conditions check. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-606.
Medium [CVE-2026-20731] Denial of Service via Improper Buffer Restrictions
Denial of Service via Improper Buffer Restrictions. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-131.
Medium [CVE-2026-73075] Out-of-bounds Access in Popup Opacity Handling
Out-of-bounds Access in Popup Opacity Handling. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-125.
Medium [CVE-2026-73074] Heap buffer overflow via integer wraparound in text property handling
Heap buffer overflow via integer wraparound in text property handling. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-190.
Medium [CVE-2026-19078] Open redirect vulnerability enables phishing via unvalidated parameter.
Open redirect vulnerability enables phishing via unvalidated parameter. Red Hat rates this low (CVSS 4.3). Weakness: CWE-601. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Medium [CVE-2026-14180] Undertow:HTTP request smuggling via oversized chunk-size bit overlap
Undertow:HTTP request smuggling via oversized chunk-size bit overlap. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-444. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apache Camel - HawtIO 4; Red Hat Data Grid 8; Red Hat Enterprise Linux 10; and 9 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; and 5 more.
Medium [CVE-2026-73070] Stack Buffer Overflow via unbounded socket connections
Stack Buffer Overflow via unbounded socket connections. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-120. Red Hat lists fixing advisory RHSA-2026:56636 with package vim-main-9.2.967-1.hum1.
Medium [CVE-2026-9214] Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality
Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality.
Medium [CVE-2026-11738] Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to router software and functionality. Affected products named by the advisory: R7000; RAXE500; RS700.
Medium [CVE-2026-11739] command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device
A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker in the middle) to compromise the confidentiality and integrity of the affected device. Affected products named by the advisory: MR60; MR70; MR90; MS60; and 4 more. Affected products named by the advisory: MS70; MS90; RAX20; RAX200.
Medium [CVE-2026-11737] Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software and functionality
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification to the device software functionality. Affected products named by the advisory: RAX20; RAX41; RAX41v2; RAX42; and 4 more. Affected products named by the advisory: RAX42v2; RAX43; RAX43v2; RAX45.
Medium [CVE-2026-11814] command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device
A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to intercept and modify local network traffic (attacker-in-the-middle) to compromise the confidentiality and integrity of the affected device. This issue is limited to certain region-specific SKUs. Affected products named by the advisory: BE9300; MR60; MS60; R6700AX; and 4 more. Affected products named by the advisory: RAX10; RAX120; RAX120v2; RAX20.
Medium [CVE-2026-71193] cross-tenant DNS zone overlap via pool-scoped ownership checks when using AttributeFilter scheduler
cross-tenant DNS zone overlap via pool-scoped ownership checks when using AttributeFilter scheduler. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-863. Affected products named by the advisory: Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-71194] mDNS NOTIFY handler DoS via pool-blind zone lookup
mDNS NOTIFY handler DoS via pool-blind zone lookup. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-863. Affected products named by the advisory: Red Hat OpenStack Platform 13 (Queens); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; Red Hat OpenStack Platform 18.0.
Medium [CVE-2026-73067] Denial of Service due to crafted data model
Denial of Service due to crafted data model. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125.
Medium [CVE-2026-72745] Information disclosure and memory corruption via malformed Kerberos GSS Wrap token
Information disclosure and memory corruption via malformed Kerberos GSS Wrap token. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-823. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: freerdp.
Medium [CVE-2026-33922] Arbitrary file deletion via path traversal in Offline archives functionality
Arbitrary file deletion via path traversal in Offline archives functionality. Red Hat rates this moderate (CVSS 6). Weakness: CWE-22.