Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

High7.0Vendor: MediumRed Hat Updated

High [CVE-2026-74637] Fix group leader use-after-free after sibling detach

Fix group leader use-after-free after sibling detach. Red Hat rates this moderate (CVSS 7). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74637
Linux Kernel
Aug 22, 2026
Critical9.1Vendor: MediumRed Hat Updated

Critical [CVE-2026-66786] ipsec.conf stanza injection via remote-supplied CableName and Subnets

ipsec.conf stanza injection via remote-supplied CableName and Subnets. Red Hat rates this moderate (CVSS 9.1). Weakness: CWE-94.

CVE-2026-66786
Unclassified
Aug 21, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-63125] Incus vulnerable to root RCE via image backup.yaml symlink

Incus vulnerable to root RCE via image backup.yaml symlink. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-61.

CVE-2026-63125
Unclassified
Aug 21, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-62941] Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge

Cross-project instance copy bypasses target project restrictions via TOCTOU in config merge. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-367.

CVE-2026-62941
Unclassified
Aug 21, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-62940] Incus has a project restriction bypass via instance migration config override

Incus has a project restriction bypass via instance migration config override. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-863.

CVE-2026-62940
Unclassified
Aug 21, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-62867] Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution

Incus has an argument injection in storage volume block.create_options that leads to arbitrary command execution. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-88.

CVE-2026-62867
Unclassified
Aug 21, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-48769] Incus has an arbitrary file write on its client due to trusted image hash

Incus has an arbitrary file write on its client due to trusted image hash. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-345.

CVE-2026-48769
Unclassified
Aug 21, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-48755] Incus has an argument injection in backup compression algorithm leading to AFW and ACE

Incus has an argument injection in backup compression algorithm leading to AFW and ACE. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-88.

CVE-2026-48755
Unclassified
Aug 21, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-48753] Incus has an arbitrary file write via path traversal in S3 multipart upload

Incus has an arbitrary file write via path traversal in S3 multipart upload. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-22.

CVE-2026-48753
Unclassified
Aug 21, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-48752] Incus has arbitrary file read+write on host via templates/ symlink in malicious image

Incus has arbitrary file read+write on host via templates/ symlink in malicious image. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-61.

CVE-2026-48752
Unclassified
Aug 21, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-48751] Incus has a restricted project bypass leading to arbitrary command execution

Incus has a restricted project bypass leading to arbitrary command execution. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-863.

CVE-2026-48751
Unclassified
Aug 21, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-48750] Incus has an arbitrary file write on host via `exec-output` symlink in crafted image

Incus has an arbitrary file write on host via `exec-output` symlink in crafted image. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-61.

CVE-2026-48750
Unclassified
Aug 21, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-48749] Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image

Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-61.

CVE-2026-48749
Unclassified
Aug 21, 2026
High7.1Red Hat Updated

High [CVE-2026-77219] Heap over-read leading to information disclosure via crafted image

Heap over-read leading to information disclosure via crafted image. Red Hat rates this important (CVSS 7.1). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: emacs.

CVE-2026-77219
Red Hat Enterprise Linux
Aug 21, 2026
High7.5Red Hat Updated

High [CVE-2026-54789] Denial of Service via malformed state cookie parsing

Denial of Service via malformed state cookie parsing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: mod_auth_openidc.

CVE-2026-54789
Red Hat Enterprise Linux
Aug 21, 2026
High7.3Red Hat Updated

High [CVE-2026-49114] Arbitrary file write via symlink following and path traversal

Arbitrary file write via symlink following and path traversal. Red Hat rates this important (CVSS 7.3). Weakness: CWE-367.

CVE-2026-49114
Unclassified
Aug 21, 2026
High7.1Red Hat

High [CVE-2026-77682] JavaScript code injection in autofill via unsanitized CSS selector from element id

JavaScript code injection in autofill via unsanitized CSS selector from element id. Red Hat rates this important (CVSS 7.1). Weakness: CWE-94.

CVE-2026-77682
Unclassified
Aug 21, 2026
High7.8Red Hat Updated

High [CVE-2026-74581] use-after-free in fib6_rule_suppress due to stale res->rt6 pointer

use-after-free in fib6_rule_suppress due to stale res->rt6 pointer. Red Hat rates this important (CVSS 7.8). Weakness: CWE-416. Red Hat lists fixing advisory RHSA-2026:60485 with package kernel-0:5.14.0-427.147.1.el9_4, kernel-0:5.14.0-687.42.1.el9_8, kernel-0:5.14.0-570.136.1.el9_6, kernel-0:4.18.0-372.209.1.el8_6. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8.

CVE-2026-74581
Unclassified
Aug 21, 2026
High7.8Red Hat Updated

High [CVE-2026-74583] fix fastmap use-after-free on filter

fix fastmap use-after-free on filter. Red Hat rates this important (CVSS 7.8). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat package: kernel-rt.

CVE-2026-74583
Linux Kernel
Aug 21, 2026
High7.3Red Hat Updated

High [CVE-2026-74580] reset the vring metadata cache on vring reconfiguration

reset the vring metadata cache on vring reconfiguration. Red Hat rates this important (CVSS 7.3). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.

CVE-2026-74580
Linux Kernel
Aug 21, 2026