Complete feed
Action required
Critical/high still unreviewed, or CISA KEV listed
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Critical [CVE-2026-31633] Linux Kernel Vulnerability in NetApp Products
Linux kernel versions 6.16-rc1 through 6.18.22, 6.19-rc1 through 6.19.12, and 6.20-rc1 through 7.0-rc7 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Critical [CVE-2026-8926] Libcurl Vulnerability in NetApp Products
Libcurl versions 8.11.1 prior to 8.21.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Critical [CVE-2026-11856] Libcurl Vulnerability in NetApp Products
Libcurl versions 7.10.6 prior to 8.21.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Critical [CVE-2026-11564] Libcurl Vulnerability in NetApp Products
Libcurl versions 8.17.0 prior to 8.21.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Critical [CVE-2026-9079] Libcurl Vulnerability in NetApp Products
Libcurl versions 8.8.0 prior to 8.21.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS). NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Critical [CVE-2026-8924] Libcurl Vulnerability in NetApp Products
Libcurl versions 7.46.0 prior to 8.21.0 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
Critical [CVE-2026-52680] Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource
Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote attacker who can access the REST batch upload endpoint can provide path traversal sequences in the filename and cause the Kyuubi server process to write controlled content outside the intended upload directory, subject to filesystem permissions. This issue affects Apache Kyuubi: from 1.7.0 through 1.11.1. Users are recommended to upgrade to version 1.12.0, which fixes the issue.
Critical [CVE-2026-28812] UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges
UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommended to upgrade to version 2.12.4 or newer which fixes this issue.
Critical [CVE-2026-47876] VMXNET3 out-of-bounds write vulnerability
VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue. Affected products named by the advisory: Cloud Foundation; vSphere Foundation; Telco Cloud Platform.
Critical [CVE-2026-59309] vCenter: VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service.
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system. Affected products named by the advisory: Cloud Foundation; vSphere Foundation; Telco Cloud Infrastructure; Telco Cloud Platform.
Critical [CVE-2026-59310] vCenter: VMware vCenter contains a directory traversal vulnerability in the Syslog server.
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code. Affected products named by the advisory: Cloud Foundation; vSphere Foundation; Telco Cloud Infrastructure; Telco Cloud Platform.
Critical [CVE-2026-18363] Account compromise via password reset token bypass
Account compromise via password reset token bypass. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-640.
Critical [CVE-2026-44092] Integrity and availability loss via malicious MQTT input injection
Integrity and availability loss via malicious MQTT input injection. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-94.
Critical [CVE-2026-17893] Insufficient validation of untrusted input in Updater
Insufficient validation of untrusted input in Updater. Red Hat rates this moderate (CVSS 9). Weakness: CWE-1286.
Critical [CVE-2026-17890] Insufficient validation of untrusted input in DevTools
Insufficient validation of untrusted input in DevTools. Red Hat rates this moderate (CVSS 9). Weakness: CWE-1286.
Critical [CVE-2026-17848] Insufficient validation of untrusted input in Codecs
Insufficient validation of untrusted input in Codecs. Red Hat rates this moderate (CVSS 9.6). Weakness: CWE-190.
Critical [CVE-2026-17850] Inappropriate implementation in Permissions
Inappropriate implementation in Permissions. Red Hat rates this moderate (CVSS 9.3). Weakness: CWE-346.
Critical [CVE-2026-17832] Use after free in ANGLE
Use after free in ANGLE. Red Hat rates this moderate (CVSS 9). Weakness: CWE-825.
Critical [CVE-2026-17811] Use after free in ANGLE
Use after free in ANGLE. Red Hat rates this moderate (CVSS 9.6). Weakness: CWE-825.
Critical [CVE-2026-17806] Insufficient validation of untrusted input in Extensions
Insufficient validation of untrusted input in Extensions. Red Hat rates this moderate (CVSS 9). Weakness: CWE-1289.