Complete feed
Recently updated
Advisories the vendor has revised
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
High [CVE-2026-66798] Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods
Restore.spec.hooks passed verbatim to Velero Restore — arbitrary command execution in restored pods. Red Hat rates this important (CVSS 8.8). Weakness: CWE-77. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/cluster-backup-rhel9-operator:1787684668, rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-66799] Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement
Restore.spec.namespaceMapping pass-through enables cross-namespace Secret/ConfigMap placement. Red Hat rates this important (CVSS 7.1). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:60390 with package rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178, rhacm2/cluster-backup-rhel9-operator:1787259060. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-66800] CleanupAll triggers unguarded cluster-wide mass-delete via operator ServiceAccount
CleanupAll triggers unguarded cluster-wide mass-delete via operator ServiceAccount. Red Hat rates this important (CVSS 7.1). Weakness: CWE-862. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/cluster-backup-rhel9-operator:1787684668, rhacm2/cluster-backup-rhel9-operator:1787238500, rhacm2/cluster-backup-rhel9-operator:1787227576, rhacm2/cluster-backup-rhel9-operator:1787183178. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.
High [CVE-2026-62901] .NET:.NET Denial of Service Vulnerability
.NET:.NET Denial of Service Vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-606. Red Hat lists fixing advisory RHSA-2026:54542 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet8.0-0:8.0.130-1.el8_10, dotnet9.0-0:9.0.120-1.el9_6, dotnet10.0-0:10.0.111-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-62909] .NET:.NET Elevation of Privilege Vulnerability
.NET:.NET Elevation of Privilege Vulnerability. Red Hat rates this important (CVSS 7.8). Weakness: CWE-252. Red Hat lists fixing advisory RHSA-2026:54542 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet8.0-0:8.0.130-1.el8_10, dotnet9.0-0:9.0.120-1.el9_6, dotnet10.0-0:10.0.111-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-73266] tenant-controlled ClusterClaim labels propagated to ManagedCluster enabling cross-tenant ManagedClusterSet join
tenant-controlled ClusterClaim labels propagated to ManagedCluster enabling cross-tenant ManagedClusterSet join. Red Hat rates this important (CVSS 7.1). Weakness: CWE-441. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/clusterclaims-controller-rhel9:1787259112, multicluster-engine/clusterclaims-controller-rhel9:1786577950, multicluster-engine/clusterclaims-controller-rhel9:1787239442, multicluster-engine/clusterclaims-controller-rhel9:1787259059. Affected product named by the advisory: Multicluster Engine for Kubernetes.
High [CVE-2026-73267] ManagedCluster deletion keyed solely on ClusterClaim.Spec.Namespace with no ownership check
ManagedCluster deletion keyed solely on ClusterClaim. Spec. Namespace with no ownership check. Red Hat rates this important (CVSS 7.7). Weakness: CWE-602. Red Hat lists fixing advisory RHSA-2026:59593 with package multicluster-engine/clusterclaims-controller-rhel9:1787259112, multicluster-engine/clusterclaims-controller-rhel9:1786577950, multicluster-engine/clusterclaims-controller-rhel9:1787239442, multicluster-engine/clusterclaims-controller-rhel9:1787259059. Affected products named by the advisory: multicluster engine for Kubernetes 2.10; multicluster engine for Kubernetes 2.11; multicluster engine for Kubernetes 2.17; multicluster engine for Kubernetes 2.6; and 2 more. Affected products named by the advisory: multicluster engine for Kubernetes 2.8; multicluster engine for Kubernetes 2.9.
Medium [CVE-2026-18710] Credential disclosure via cleartext logging during client initialization
Credential disclosure via cleartext logging during client initialization. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-312. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Debezium 3; Red Hat build of Quarkus.
Medium [CVE-2026-73242] Out-of-bounds memory access in Kerberos decryption
Out-of-bounds memory access in Kerberos decryption. Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:61378 with package freerdp-2:3.10.3-12.el10_2.10. Affected product named by the advisory: Red Hat Enterprise Linux 10.
Medium [CVE-2026-71474] Pull-secret bearer token written to logs on non-200 CCX response
Pull-secret bearer token written to logs on non-200 CCX response. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-532. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/insights-client-rhel9:1787227689, rhacm2/insights-client-rhel9:1787184541, rhacm2/insights-client-rhel9:1787688993, rhacm2/insights-client-rhel9:1787259125. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Medium [CVE-2026-71468] Cross-user bearer-token reuse via global federation-config cache
Cross-user bearer-token reuse via global federation-config cache. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/acm-search-v2-api-rhel9:1787191668, rhacm2/acm-search-v2-api-rhel9:1787263804, rhacm2/acm-search-v2-api-rhel9:1787238618, rhacm2/acm-search-v2-api-rhel9:1787229541. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Medium [CVE-2026-71475] Spoke-controlled ClusterID injected unencoded into Insights API URL path
Spoke-controlled ClusterID injected unencoded into Insights API URL path. Red Hat rates this moderate (CVSS 5). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/insights-client-rhel9:1787227689, rhacm2/insights-client-rhel9:1787184541, rhacm2/insights-client-rhel9:1787259125, rhacm2/insights-client-rhel9:1787238585. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; Red Hat Advanced Cluster Management for Kubernetes 2.16; and 1 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.17.
Medium [CVE-2026-71845] CCX_TOKEN bearer credential logged in clear text at startup via setDefault
CCX_TOKEN bearer credential logged in clear text at startup via setDefault(). Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-532. Red Hat lists fixing advisory RHSA-2026:60391 with package rhacm2/insights-client-rhel9:1787227689, rhacm2/insights-client-rhel9:1787184541, rhacm2/insights-client-rhel9:1787688993, rhacm2/insights-client-rhel9:1787259125. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.11; Red Hat Advanced Cluster Management for Kubernetes 2.13; Red Hat Advanced Cluster Management for Kubernetes 2.14; Red Hat Advanced Cluster Management for Kubernetes 2.15; and 2 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.16; Red Hat Advanced Cluster Management for Kubernetes 2.17.
Medium [CVE-2026-73283] Tunnel forwarding restriction bypass
Tunnel forwarding restriction bypass. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-305. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat package: openssh.
Medium [CVE-2026-73282] Information disclosure and data corruption via use-after-free in ssh client
Information disclosure and data corruption via use-after-free in ssh client. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; Red Hat package: openssh.
Medium [CVE-2026-73229] Django REST framework: Information disclosure via improper permission checks in AdminRenderer
Django REST framework: Information disclosure via improper permission checks in AdminRenderer. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-425. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Discovery 2; Red Hat Satellite 6; Red Hat Update Infrastructure 4 for Cloud Providers; and 1 more. Affected products named by the advisory: Red Hat Update Infrastructure 5.
Medium [CVE-2026-73228] Django REST framework: Denial of Service via oversized request bodies
Django REST framework: Denial of Service via oversized request bodies. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-770. Affected products named by the advisory: Red Hat Ansible Automation Platform 2; Red Hat Discovery 2; Red Hat Satellite 6; Red Hat Update Infrastructure 4 for Cloud Providers; and 1 more. Affected products named by the advisory: Red Hat Update Infrastructure 5.
Medium [CVE-2026-73216] Authenticated client can exhaust relay capacity via quota bypass
Authenticated client can exhaust relay capacity via quota bypass. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-911.
Medium [CVE-2026-73215] Denial of Service due to incorrect port allocation
Denial of Service due to incorrect port allocation. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-772.
Medium [CVE-2026-72712] Denial of Service via zero-length TCP option packet
Denial of Service via zero-length TCP option packet. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-835. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: nmap.