Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-53794] Denial of Service via --max-alloc=0 logic error
Denial of Service via --max-alloc=0 logic error. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
Medium [CVE-2026-53792] Denial of Service via out-of-bounds read with crafted checksum block
Denial of Service via out-of-bounds read with crafted checksum block. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-129. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: rsync.
Medium [CVE-2026-73506] Terminal escape sequence injection via unsanitized prompt data
Terminal escape sequence injection via unsanitized prompt data. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-791.
Medium [CVE-2026-73584] Privileged file corruption and denial of service via insecure temporary file handling
Privileged file corruption and denial of service via insecure temporary file handling. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-377. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: sblim-sfcb.
Medium [CVE-2026-73583] Unsafe deserialization in sblim-sfcb provider-manager IPC allows out-of-bounds memory access via malformed OperationHdr
Unsafe deserialization in sblim-sfcb provider-manager IPC allows out-of-bounds memory access via malformed OperationHdr. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: sblim-sfcb.
Medium [CVE-2026-73585] Insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack
Insecure temporary file creation in sblim-cmpi-base provider registration scripts allows local symlink attack. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-377. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-73621] Arbitrary File Truncation via Commit.count Argument Injection
Arbitrary File Truncation via Commit.count() Argument Injection. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-88. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.
Medium [CVE-2026-73619] Arbitrary file read vulnerability via `Repo.archive `
Arbitrary file read vulnerability via `Repo.archive()`. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-22. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Pen Drive Powered by Red Hat Lightspeed; Red Hat AI Inference Server; and 7 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat Hardened Images; Red Hat OpenShift AI (RHOAI); and 3 more.
Medium [CVE-2026-19694] Heap-based Buffer Overflow in Wireshark
Heap-based Buffer Overflow in Wireshark. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-122.
Medium [CVE-2026-19695] Stack-based Buffer Overflow in Wireshark
Stack-based Buffer Overflow in Wireshark. Red Hat rates this moderate (CVSS 4.7). Weakness: CWE-121.
Medium [CVE-2026-19696] Out-of-bounds Write in Wireshark
Out-of-bounds Write in Wireshark. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-787.
Medium [CVE-2026-18728] Integer underflow in iscsiuio IPv4 DHCP parsing
Integer underflow in iscsiuio IPv4 DHCP parsing. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-191. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9.
Medium [CVE-2026-68454] Fix handling of AIF enable without AISB
Fix handling of AIF enable without AISB. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Low [CVE-2026-55987] Administrator-deactivated accounts can be reactivated via OAuth2 sign-in
Administrator-deactivated accounts can be reactivated via OAuth2 sign-in. Red Hat rates this low (CVSS 3.5). Weakness: CWE-807.
Low [CVE-2026-55984] Denial of Service via Null Pointer Dereference in AddTime API
Denial of Service via Null Pointer Dereference in AddTime API. Red Hat rates this low (CVSS 2.7). Weakness: CWE-476.
Low [CVE-2026-73626] Extension allowlist bypass allows unauthorized installations
Extension allowlist bypass allows unauthorized installations. Red Hat rates this low. Weakness: CWE-358.
Critical [CVE-2026-71471] Hub Search CR Collector.ImageOverride propagated to every spoke as arbitrary container image
Hub Search CR Collector. ImageOverride propagated to every spoke as arbitrary container image. Red Hat rates this important (CVSS 9). Weakness: CWE-829. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-rhel9:1787682033, rhacm2/acm-search-v2-rhel9:1787681674, rhacm2/acm-search-v2-rhel9:1787681686, rhacm2/acm-search-v2-rhel9:1787682112. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Critical [CVE-2026-73501] ValidationHandler.Load Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
ValidationHandler. Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:59030 with package grafana13-2-main-13.2.0-0.1.1.hum1, hugo-main-0.165.0-0.1.hum1, grafana13-1-main-13.1.3-0.2.hum1, grafana12-4-main-12.4.9-0.4.hum1. Affected products named by the advisory: Red Hat Hardened Images; Migration Toolkit for Applications 8; OpenShift Serverless; Red Hat OpenShift Container Platform 4; and 2 more. Affected products named by the advisory: Red Hat OpenShift GitOps; Red Hat OpenStack Platform 18.0.
Critical [CVE-2026-72508] hub and spoke ServiceAccounts bound to wildcard RBAC (*/*/*)
hub and spoke ServiceAccounts bound to wildcard RBAC (*/*/*). Red Hat rates this important (CVSS 9.9). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicluster-operators-subscription-rhel9:1787242108, rhacm2/multicluster-operators-subscription-rhel9:1787263693, rhacm2/multicluster-operators-subscription-rhel9:1787242321, rhacm2/multicluster-operators-subscription-rhel9:1787240030. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Critical [CVE-2026-70398] GitOpsCluster.spec.argoServer.argoNamespace writes spoke bearer tokens to attacker-chosen namespace
GitOpsCluster.spec.argoServer.argoNamespace writes spoke bearer tokens to attacker-chosen namespace. Red Hat rates this important (CVSS 9.6). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/multicloud-integrations-rhel9:1787252179, rhacm2/multicloud-integrations-rhel9:1787260689, rhacm2/multicloud-integrations-rhel9:1787259106, rhacm2/multicloud-integrations-rhel9:1787243221. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.