Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-68440] fix heap overflow when reading module EEPROM
fix heap overflow when reading module EEPROM. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-787.
Medium [CVE-2026-68445] Prevent shader BO mappings from becoming writable
Prevent shader BO mappings from becoming writable. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-179. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-68434] Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms
Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-68441] Handle TC_ACT_REDIRECT from qdisc filter chains
Handle TC_ACT_REDIRECT from qdisc filter chains. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; and 2 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Medium [CVE-2026-68435] Fix address space mismatch in kexec command line lookup
Fix address space mismatch in kexec command line lookup. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-822. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.
Medium [CVE-2026-68444] Fix NULL dereference in ffa_partition_info_get
Fix NULL dereference in ffa_partition_info_get(). Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: kernel-rt.
Medium [CVE-2026-68437] Fit paired fragment job in the correct CCCB
Fit paired fragment job in the correct CCCB. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-1285. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.
Medium [CVE-2026-68443] (gigabyte_waterforce) Stop device IO before calling hid_hw_stop
(gigabyte_waterforce) Stop device IO before calling hid_hw_stop. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: kernel.
Medium [CVE-2026-68449] fix infinite loop in NCQ tag completion bit-scanning
fix infinite loop in NCQ tag completion bit-scanning. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: kernel-rt.
Medium [CVE-2026-68447] clamp v9 CRIU control stack checkpoint copy to BO size
clamp v9 CRIU control stack checkpoint copy to BO size. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Low [CVE-2026-73492] Arbitrary code execution due to URI scheme bypass
Arbitrary code execution due to URI scheme bypass. Red Hat rates this low (CVSS 3.7). Weakness: CWE-76. Affected products named by the advisory: Red Hat 3scale API Management Platform 2; Red Hat Satellite 6.
Low [CVE-2026-73491] Cross-Site Scripting via malformed `javascript:` URI parsing
Cross-Site Scripting via malformed `javascript:` URI parsing. Red Hat rates this low (CVSS 3.7). Weakness: CWE-1289.
Critical [CVE-2026-73213] Server-Side Request Forgery via incorrect IPv6 comparison
Server-Side Request Forgery via incorrect IPv6 comparison. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-918.
Critical [CVE-2026-10579] auth bypass in Picketlink SAML unsolicited-response
auth bypass in Picketlink SAML unsolicited-response. Red Hat rates this critical (CVSS 9.8). Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected product named by the advisory: Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7.
Critical [CVE-2026-73268] spec.install.overrideJob allows arbitrary Job spec injection
spec.install.overrideJob allows arbitrary Job spec injection. Red Hat rates this important (CVSS 9.9). Weakness: CWE-94. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/cluster-curator-controller-rhel9:1787238383, multicluster-engine/cluster-curator-controller-rhel9:1787264185, multicluster-engine/cluster-curator-controller-rhel9:1786750700, multicluster-engine/cluster-curator-controller-rhel9:1787259011. Affected product named by the advisory: Multicluster Engine for Kubernetes.
Critical [CVE-2026-73269] tenant-controllable trigger creates ClusterRoleBinding granting cluster-wide secrets access to namespace-local SA
tenant-controllable trigger creates ClusterRoleBinding granting cluster-wide secrets access to namespace-local SA. Red Hat rates this important (CVSS 9.9). Weakness: CWE-269. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/cluster-curator-controller-rhel9:1787238383, multicluster-engine/cluster-curator-controller-rhel9:1787264185, multicluster-engine/cluster-curator-controller-rhel9:1786750700, multicluster-engine/cluster-curator-controller-rhel9:1787259011. Affected product named by the advisory: Multicluster Engine for Kubernetes.
High [CVE-2026-5917] Arbitrary code execution via shell command injection in SSH backend
Arbitrary code execution via shell command injection in SSH backend. Red Hat rates this important (CVSS 8.8). Weakness: CWE-78. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux AI (RHEL AI) 3; and 2 more. Affected products named by the advisory: Red Hat package: rust; Red Hat package: libgit2.
High [CVE-2026-29036] Data corruption and unauthorized modification via JSON Pointer escape decoding
Data corruption and unauthorized modification via JSON Pointer escape decoding. Red Hat rates this important (CVSS 7.5). Weakness: CWE-386.
High [CVE-2026-19560] Arbitrary code execution via use-after-free in Blink
Arbitrary code execution via use-after-free in Blink. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-19559] Arbitrary code execution via use after free in HTML
Arbitrary code execution via use after free in HTML. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416.