Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-19557] Sandbox escape via use-after-free in TabStrip
Sandbox escape via use-after-free in TabStrip. Red Hat rates this important (CVSS 8.2). Weakness: CWE-825.
High [CVE-2026-19558] Arbitrary code execution via malicious extension installation
Arbitrary code execution via malicious extension installation. Red Hat rates this important (CVSS 7.3). Weakness: CWE-416.
High [CVE-2026-19556] Arbitrary code execution via use-after-free in V8
Arbitrary code execution via use-after-free in V8. Red Hat rates this important (CVSS 8.8). Weakness: CWE-416.
High [CVE-2026-19550] trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes
trust-fetch-domains uses trust-read ACI to gate a privileged AD trust refresh, allowing unauthorized LDAP writes. Red Hat rates this important (CVSS 8.2). Weakness: CWE-863. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
High [CVE-2026-71290] Server impersonation via improper TLS hostname verification
Server impersonation via improper TLS hostname verification. Red Hat rates this important (CVSS 8.1). Weakness: CWE-295.
High [CVE-2026-29035] Arbitrary code execution via crafted WebSocket frames
Arbitrary code execution via crafted WebSocket frames. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787.
High [CVE-2026-73241] Authentication bypass via incorrect RDSTLS PDU handling
Authentication bypass via incorrect RDSTLS PDU handling. Red Hat rates this important (CVSS 7.5). Weakness: CWE-287. Red Hat lists fixing advisory RHSA-2026:61378 with package freerdp-2:3.10.3-12.el10_2.10. Affected product named by the advisory: Red Hat Enterprise Linux 10.
High [CVE-2026-73231] @faker-js/faker: Faker: Arbitrary Code Execution via attacker-controlled fake templates
@faker-js/faker: Faker: Arbitrary Code Execution via attacker-controlled fake templates. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected products named by the advisory: Cryostat 4; Red Hat AMQ Broker 7; Red Hat Build of Keycloak; Red Hat Enterprise Linux 10; and 4 more. Affected products named by the advisory: Red Hat Hardened Images; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; Red Hat package: grafana.
High [CVE-2026-71467] Authentication bypass on /federated via Upgrade: websocket header spoofing
Authentication bypass on /federated via Upgrade: websocket header spoofing. Red Hat rates this important (CVSS 7.5). Weakness: CWE-287. Red Hat lists fixing advisory RHSA-2026:60386 with package rhacm2/acm-search-v2-api-rhel9:1787229541. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.17.
High [CVE-2026-48804] Denial of Service via binary attachment accumulation
Denial of Service via binary attachment accumulation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-73214] Denial of Service via unverified DTLS session state
Denial of Service via unverified DTLS session state. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.
High [CVE-2026-73212] Server-Side Request Forgery and Remote Code Execution via IP address canonicalization bypass
Server-Side Request Forgery and Remote Code Execution via IP address canonicalization bypass. Red Hat rates this important (CVSS 7.7). Weakness: CWE-1389.
High [CVE-2026-73089] Denial of Service via unbounded memory growth from distinct query results
Denial of Service via unbounded memory growth from distinct query results. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:56338 with package ansible-automation-platform/automation-portal:1787047114, grafana13-1-main-13.1.3-0.1.1.hum1, openshift4/nmstate-console-plugin-rhel9:1787590372, discovery/discovery-ui-rhel9:1786634825. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Gatekeeper 3; Migration Toolkit for Containers; and 43 more. Affected products named by the advisory: Node HealthCheck Operator; OpenShift Lightspeed; OpenShift Pipelines; OpenShift Service Mesh 3; and 39 more.
High [CVE-2026-73088] Prototype pollution leading to denial of service
Prototype pollution leading to denial of service. Red Hat rates this important (CVSS 7.5). Weakness: CWE-915. Red Hat lists fixing advisory RHSA-2026:56338 with package ansible-automation-platform/automation-portal:1787047114, grafana13-1-main-13.1.3-0.1.1.hum1, openshift4/nmstate-console-plugin-rhel9:1787590372, discovery/discovery-ui-rhel9:1786634825. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Gatekeeper 3; Migration Toolkit for Containers; and 43 more. Affected products named by the advisory: Node HealthCheck Operator; OpenShift Lightspeed; OpenShift Pipelines; OpenShift Service Mesh 3; and 39 more.
High [CVE-2026-73086] Predictable ID generation due to integer overflow
Predictable ID generation due to integer overflow. Red Hat rates this important (CVSS 7.4). Weakness: CWE-1241. Red Hat lists fixing advisory RHSA-2026:56338 with package multicluster-engine/console-mce-rhel9:1787079359, rhacm2/console-rhel9:1787339248, jaeger-main-2.20.0-0.8.hum1, multicluster-engine/console-mce-rhel9:1787264250. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Gatekeeper 3; Migration Toolkit for Containers; and 39 more. Affected products named by the advisory: Multicluster Engine for Kubernetes; Network Observability Operator; Node HealthCheck Operator; OpenShift Lightspeed; and 35 more.
High [CVE-2025-35973] Privilege escalation in Ring 0 via improper value handling
Privilege escalation in Ring 0 via improper value handling. Red Hat rates this important (CVSS 7.2). Weakness: CWE-266. Affected products named by the advisory: Confidential Compute Attestation; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux for NVIDIA 26; Red Hat OpenShift Container Platform 4; and 1 more.
High [CVE-2026-73078] Arbitrary Code Execution via Crafted Netrw Menu Entries
Arbitrary Code Execution via Crafted Netrw Menu Entries. Red Hat rates this important (CVSS 8.8). Weakness: CWE-77.
High [CVE-2026-73077] Arbitrary Code Execution via Insecure Shell Command Handling
Arbitrary Code Execution via Insecure Shell Command Handling. Red Hat rates this important (CVSS 7.3). Weakness: CWE-78.
High [CVE-2026-73076] Arbitrary command execution via crafted vimball
Arbitrary command execution via crafted vimball. Red Hat rates this important (CVSS 7.3). Weakness: CWE-78.
High [CVE-2026-73072] Heap buffer overflow allows arbitrary code execution
Heap buffer overflow allows arbitrary code execution. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: vim.