Complete feed
Security advisories & CVEs
165 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-80574] focaltech - fix array out-of-bounds in focaltech_process_rel_packet
focaltech - fix array out-of-bounds in focaltech_process_rel_packet. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-80548] Selectively expand io_mutex
Selectively expand io_mutex. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-366. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-80551] Ensure first IDAW remains constant
Ensure first IDAW remains constant. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-80579] clear fb_info->mode before deleting a videomode
clear fb_info->mode before deleting a videomode. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-80549] Move cp cleanup out of not operational
Move cp cleanup out of not operational. Red Hat rates this low (CVSS 5.5). Weakness: CWE-833. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-74745] avoid deadlock when canceling IRQ affinity notifier
avoid deadlock when canceling IRQ affinity notifier. Red Hat rates this low (CVSS 5.5). Weakness: CWE-833. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-80588] reclaim forward-allocated memory on RX path errors
reclaim forward-allocated memory on RX path errors. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-80560] do not restore privileged SR bits on sigreturn
do not restore privileged SR bits on sigreturn. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-15.
Medium [CVE-2026-73180] Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended
Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
Medium [CVE-2026-80185] unprivileged-local and adjacent-LE-peer leads to arbitrary code execution as root
unprivileged-local and adjacent-LE-peer leads to arbitrary code execution as root. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: bluez.
Medium [CVE-2026-80101] Gimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-line validation
A flaw was found in the file-xwd plugin in GIMP. This incorrect validation leads to improper bounds checking, causing a heap out-of-bounds read. This issue can result in an application crash, leading to a denial of service, or a limited information disclosure of heap memory contents into the produced image. To exploit this vulnerability, an attacker needs to convince a user to process a specially crafted XWD image with GIMP, reducing the likelihood of exploitation. Due to this reason, this flaw has been rated with a moderate severity. Red Hat severity: Moderate — CVSS 4.4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gimp.
Medium [CVE-2025-32907 +1] quadratic CPU denial of service in HTTP Range coalescing after CVE-2025-32907 fix
quadratic CPU denial of service in HTTP Range coalescing after CVE-2025-32907 fix. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-407. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: libsoup3.
Medium [CVE-2026-79258] Information disclosure via incorrect authorization
Information disclosure via incorrect authorization. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-346.
Medium [CVE-2026-79276] Privilege management bypass via crafted HTML page
Privilege management bypass via crafted HTML page. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-266.
Medium [CVE-2026-79772] Signature validation bypass via unchecked return value
Signature validation bypass via unchecked return value. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-252. Affected products named by the advisory: Red Hat 3scale API Management Platform 2; Red Hat Satellite 6.
Medium [CVE-2026-79771] Denial of Service via XSLT transform memory leak
Denial of Service via XSLT transform memory leak. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected products named by the advisory: Red Hat 3scale API Management Platform 2; Red Hat Satellite 6.
Medium [CVE-2026-79769] Process crash due to invalid memory read via programming error in internal method
Process crash due to invalid memory read via programming error in internal method. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-843. Affected products named by the advisory: Red Hat 3scale API Management Platform 2; Red Hat Satellite 6.
Medium [CVE-2026-79676] Information disclosure via path traversal with symlink bypass
Information disclosure via path traversal with symlink bypass. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-22. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-79717] blind SSRF via namespace avatar_url with no private-address restriction
blind SSRF via namespace avatar_url with no private-address restriction. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-918. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.
Medium [CVE-2026-16599] Denial of Service via crafted FTP OPIE/S-KEY authentication challenge
Denial of Service via crafted FTP OPIE/S-KEY authentication challenge. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: wget.