Complete feed
Action required
Critical/high still unreviewed, or CISA KEV listed
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-74637] Fix group leader use-after-free after sibling detach
Fix group leader use-after-free after sibling detach. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Critical [CVE-2026-66786] ipsec.conf stanza injection via remote-supplied CableName and Subnets
ipsec.conf stanza injection via remote-supplied CableName and Subnets. Red Hat rates this moderate (CVSS 9.1). Weakness: CWE-94.
Critical [CVE-2026-63125] Incus vulnerable to root RCE via image backup.yaml symlink
Incus vulnerable to root RCE via image backup.yaml symlink. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-61.
Critical [CVE-2026-62941] Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge
Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-367.
Critical [CVE-2026-62940] Incus has a project restriction bypass via instance migration config override
Incus has a project restriction bypass via instance migration config override. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-863.
Critical [CVE-2026-62867] Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution
Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-88.
Critical [CVE-2026-48769] Incus has an arbitrary file write on its client due to trusted image hash
Incus has an arbitrary file write on its client due to trusted image hash. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-345.
Critical [CVE-2026-48755] Incus has an argument injection in backup compression algorithm leading to AFW and ACE
Incus has an argument injection in backup compression algorithm leading to AFW and ACE. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-88.
Critical [CVE-2026-48753] Incus has an arbitrary file write via path traversal in S3 multipart upload
Incus has an arbitrary file write via path traversal in S3 multipart upload. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-22.
Critical [CVE-2026-48752] Incus has arbitrary file read+write on host via templates/ symlink in malicious image
Incus has arbitrary file read+write on host via templates/ symlink in malicious image. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-61.
Critical [CVE-2026-48751] Incus has a restricted project bypass leading to arbitrary command execution
Incus has a restricted project bypass leading to arbitrary command execution. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-863.
Critical [CVE-2026-48750] Incus has an arbitrary file write on host via `exec-output` symlink in crafted image
Incus has an arbitrary file write on host via `exec-output` symlink in crafted image. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-61.
Critical [CVE-2026-48749] Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image
Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-61.
High [CVE-2026-77219] Heap over-read leading to information disclosure via crafted image
Heap over-read leading to information disclosure via crafted image. Red Hat rates this important (CVSS 7.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: emacs.
High [CVE-2026-54789] Denial of Service via malformed state cookie parsing
Denial of Service via malformed state cookie parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: mod_auth_openidc.
High [CVE-2026-49114] Arbitrary file write via symlink following and path traversal
Arbitrary file write via symlink following and path traversal. Red Hat rates this important (CVSS 7.3). Weakness: CWE-367.
High [CVE-2026-77682] JavaScript code injection in autofill via unsanitized CSS selector from element id
JavaScript code injection in autofill via unsanitized CSS selector from element id. Red Hat rates this important (CVSS 7.1). Weakness: CWE-94.
High [CVE-2026-74581] use-after-free in fib6_rule_suppress due to stale res->rt6 pointer
use-after-free in fib6_rule_suppress due to stale res->rt6 pointer. Red Hat rates this important (CVSS 7.8). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:60485 with package kernel-0:5.14.0-427.147.1.el9_4, kernel-0:5.14.0-687.42.1.el9_8, kernel-0:5.14.0-570.136.1.el9_6, kernel-0:4.18.0-372.209.1.el8_6. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.
High [CVE-2026-74583] fix fastmap use-after-free on filter
fix fastmap use-after-free on filter. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat package: kernel-rt.
High [CVE-2026-74580] reset the vring metadata cache on vring reconfiguration
reset the vring metadata cache on vring reconfiguration. Red Hat rates this important (CVSS 7.3). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.