Complete feed
Security advisories & CVEs
1854 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-68168] Fix afs_edit_dir_remove to get, not find, block 0
Fix afs_edit_dir_remove() to get, not find, block 0. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-367. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat package: kernel.
Medium [CVE-2026-68344] reject descriptors that confuse probe and disconnect
reject descriptors that confuse probe and disconnect. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-843. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: kernel.
Medium [CVE-2026-68227] fix devres lifetime
fix devres lifetime. Red Hat rates this low (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-68139] Use sender devcom for MPV master-up
Use sender devcom for MPV master-up. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-68226] add ioremap return check and cleanup
add ioremap return check and cleanup. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat package: kernel-rt.
Medium [CVE-2026-68212] Fix a possible memory leak in saa7134_video_init1
Fix a possible memory leak in saa7134_video_init1. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: kernel-rt.
Medium [CVE-2026-46405] Denial of Service from unaccessible token accumulation in Kerberos authentication.
Denial of Service from unaccessible token accumulation in Kerberos authentication. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770.
Medium [CVE-2026-46358] Authentication material disclosure via incorrect audit log redaction
Authentication material disclosure via incorrect audit log redaction. Red Hat rates this moderate (CVSS 4.4). Weakness: CWE-312.
Medium [CVE-2026-66151] Global VPN Client: SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec…
SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.
Medium [CVE-2026-71870] Denial of Service via crafted PDF with large /ToUnicode streams
Denial of Service via crafted PDF with large /ToUnicode streams. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-770.
Medium [CVE-2026-15970] Authorization bypass via custom public listener
Authorization bypass via custom public listener. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-551. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-19017] Sensitive secret exfiltration via partial arbitrary file read
Sensitive secret exfiltration via partial arbitrary file read. Red Hat rates this moderate (CVSS 6.8). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-19014] Denial of Service via uncontrolled resource consumption in Connect authorization endpoint
Denial of Service via uncontrolled resource consumption in Connect authorization endpoint. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-19012] Authenticated denial of service via configuration entry
Authenticated denial of service via configuration entry. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-15. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-19016] Authorization bypass allows arbitrary session deletion via transaction API
Authorization bypass allows arbitrary session deletion via transaction API. Red Hat rates this moderate (CVSS 4.2). Weakness: CWE-639. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: grafana.
Medium [CVE-2026-71852] Denial of Service via crafted PDF with large CID font width ranges
Denial of Service via crafted PDF with large CID font width ranges. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1050.
Medium [CVE-2026-18938] Integer overflow in RPC attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems
Integer overflow in RPC attribute-array length calculation can under-allocate nested attribute storage on 32 bit systems. Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-122.
Medium [CVE-2026-19079] toctou race condition in fixfiles allows arbitrary selinux label manipulation
A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate and relabel unlabeled files under /tmp and other directories. A local attacker could exploit a race window between the file discovery and the label change operation by swapping directory components with symlinks, causing chcon to follow the symlink and modify SELinux labels on arbitrary system files. This could undermine SELinux mandatory access control protections on critical files such as /etc/shadow. Red Hat ships policycoreutils with the fixfiles script in all supported RHEL versions. The vulnerable /tmp cleanup code path has been present in fixfiles for many years. Red Hat product impact analysis is required to determine which specific shipped versions of policycoreutils include the vulnerable code and whether backporting the upstream fix is necessary. The vulnerability requires local access, winning a race condition, and an administrator running fixfiles relabel or fixfiles restore, which limits the practical attack surface. Red Hat severity: Moderate — CVSS 4.4 (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N). Weakness: CWE-367.
Medium [CVE-2026-12261] Resource poisoning via improper package archive extraction
Resource poisoning via improper package archive extraction. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-367. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-63140] Elasticsearch Vulnerability in NetApp Products
Elasticsearch versions 8.0.0 through 8.19.18, 9.0.0 through 9.3.7, and 9.4.0 through 9.4.3 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS). Successful exploitation of this vulnerability could lead to Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.