Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Medium4.3Red Hat

Medium [CVE-2026-19519] denial of service via unchecked type assertion in RPM header parser

denial of service via unchecked type assertion in RPM header parser. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-617. Affected products named by the advisory: Red Hat Advanced Cluster Security 4; Red Hat Quay 3.

CVE-2026-19519
Unclassified
Aug 11, 2026
Medium6.5Red Hat

Medium [CVE-2026-19391] Incomplete credential redaction exposes SSSD bind passwords and Pacemaker fence credentials in uploaded archives

Incomplete credential redaction exposes SSSD bind passwords and Pacemaker fence credentials in uploaded archives. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-312. Affected products named by the advisory: Pen Drive Powered by Red Hat Lightspeed; Red Hat Certification Program for Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat package: insights-core.

CVE-2026-19391
Red Hat Enterprise Linux
Aug 11, 2026
Medium5.7Red Hat

Medium [CVE-2026-5304] Privilege escalation via malicious ACAP application installation

Privilege escalation via malicious ACAP application installation. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: axis.

CVE-2026-5304
Red Hat Enterprise Linux
Aug 11, 2026
Medium6.5Red Hat

Medium [CVE-2026-24330] Arbitrary File Read via malicious archive deployment

Arbitrary File Read via malicious archive deployment. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-434. Affected products named by the advisory: Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 2 more. Affected products named by the advisory: Red Hat Process Automation 7; Red Hat Single Sign-On 7.

CVE-2026-24330
Unclassified
Aug 11, 2026
Medium4.9Red Hat

Medium [CVE-2026-24329] Denial of Service via malformed payload injection by an authenticated administrative user.

Denial of Service via malformed payload injection by an authenticated administrative user. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-91. Affected products named by the advisory: Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 2 more. Affected products named by the advisory: Red Hat Process Automation 7; Red Hat Single Sign-On 7.

CVE-2026-24329
Unclassified
Aug 11, 2026
Medium5.9Red Hat

Medium [CVE-2026-62899] .NET:.NET Core:.NET Security Feature Bypass Vulnerability

.NET:.NET Core:.NET Security Feature Bypass Vulnerability. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-444. Red Hat lists fixing advisory RHSA-2026:54542 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet8.0-0:8.0.130-1.el8_10, dotnet9.0-0:9.0.120-1.el9_6, dotnet10.0-0:10.0.111-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-62899
Unclassified
Aug 11, 2026
Medium5.9Red Hat

Medium [CVE-2026-62900] .NET:.NET Information Disclosure Vulnerability

.NET:.NET Information Disclosure Vulnerability. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-212. Red Hat lists fixing advisory RHSA-2026:54542 with package dotnet8-0-main-8.0.130-0.1.hum1, dotnet8.0-0:8.0.130-1.el8_10, dotnet9.0-0:9.0.120-1.el9_6, dotnet10.0-0:10.0.111-1.el9_8. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-62900
Unclassified
Aug 11, 2026
Low3.5Red Hat

Low [CVE-2026-73281] ssh-agent allows remote execution of local operations

ssh-agent allows remote execution of local operations. Red Hat rates this low (CVSS 3.5). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Hardened Images; Red Hat OpenShift Container Platform 4; and 1 more. Affected products named by the advisory: Red Hat package: openssh.

CVE-2026-73281
Red Hat Enterprise Linux
Aug 11, 2026
Low3.3Red Hat

Low [CVE-2026-73071] Denial of Service via Use-After-Free in JSON Decoding

Denial of Service via Use-After-Free in JSON Decoding. Red Hat rates this low (CVSS 3.3). Weakness: CWE-416.

CVE-2026-73071
Unclassified
Aug 11, 2026
Critical9.9Red Hat

Critical [CVE-2026-18948] Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server

Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server. Red Hat rates this critical (CVSS 9.9). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-feature-server-rhel9:1787068065, rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786110033, rhoai/odh-feature-server-rhel9:1786107278. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.

CVE-2026-18948
Unclassified
Aug 10, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-14450] Privilege escalation via forged HTTP headers due to missing authentication

Privilege escalation via forged HTTP headers due to missing authentication. Red Hat rates this important (CVSS 9.9). Weakness: CWE-290. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-maas-api-rhel9:1785850409, rhoai/odh-maas-api-rhel9:1787153683. Affected product named by the advisory: Red Hat OpenShift AI 3.4.

CVE-2026-14450
Unclassified
Aug 10, 2026
Critical9.9Red Hat

Critical [CVE-2026-66801] shared Kafka gh-spec topic Write ACL plus spoofable CloudEvent source enables fleet-wide cluster-admin from any compromised managed hub

shared Kafka gh-spec topic Write ACL plus spoofable CloudEvent source enables fleet-wide cluster-admin from any compromised managed hub. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-290. Red Hat lists fixing advisory RHSA-2026:54577 with package multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786621416, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786071343, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1786067967, multicluster-globalhub/multicluster-globalhub-rhel9-operator:1785773214.

CVE-2026-66801
Unclassified
Aug 10, 2026
High7.4Red Hat

High [CVE-2026-66806] TLS verification disabled when sending hub pull-secret to console.redhat.com

TLS verification disabled when sending hub pull-secret to console.redhat.com. Red Hat rates this important (CVSS 7.4). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:59579 with package multicluster-engine/console-mce-rhel9:1787264250, rhacm2/console-rhel9:1787687062. Affected products named by the advisory: Multicluster Engine for Kubernetes; Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66806
Unclassified
Aug 10, 2026
High7.8Red Hat

High [CVE-2026-72913] Arbitrary Code Execution via Chained DCS Escape Sequences

Arbitrary Code Execution via Chained DCS Escape Sequences. Red Hat rates this important (CVSS 7.8). Weakness: CWE-78. Affected products named by the advisory: External Secrets Operator for Red Hat OpenShift; Logging Subsystem for Red Hat OpenShift; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gvisor-tap-vsock.

CVE-2026-72913
Red Hat Enterprise Linux
Aug 10, 2026
High7.8Red Hat

High [CVE-2026-63622] swtpm privilege escalation via symlink following

swtpm privilege escalation via symlink following. Red Hat rates this important (CVSS 7.8). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux for NVIDIA 26; Red Hat package: libvirt.

CVE-2026-63622
Red Hat Enterprise Linux
Aug 10, 2026
High8.8Vendor: CriticalRed Hat

High [CVE-2026-18982] RHOAI fork aggregates training job create onto native edit/admin ClusterRoles

RHOAI fork aggregates training job create onto native edit/admin ClusterRoles. Red Hat rates this critical (CVSS 8.8). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-training-operator-rhel9:1787361677, rhoai/odh-training-operator-rhel9:1784814352, rhoai/odh-training-operator-rhel9:1785187053, rhoai/odh-training-operator-rhel9:1785188461. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.

CVE-2026-18982
Unclassified
Aug 10, 2026
High8.8Vendor: CriticalRed Hat

High [CVE-2026-18951] [Trainer v2 Security] TRN-02: RHOAI overlay aggregates trainjobs CRUD into standard edit ClusterRole

[Trainer v2 Security] TRN-02: RHOAI overlay aggregates trainjobs CRUD into standard edit ClusterRole. Red Hat rates this critical (CVSS 8.8). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-training-operator-rhel9:1787361677, rhoai/odh-training-operator-rhel9:1784814352, rhoai/odh-training-operator-rhel9:1785188461. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.

CVE-2026-18951
Unclassified
Aug 10, 2026
High8.8Vendor: CriticalRed Hat

High [CVE-2026-18950] Confused-deputy privilege escalation via unchecked roleRef in RoleBinding creation

Confused-deputy privilege escalation via unchecked roleRef in RoleBinding creation. Red Hat rates this critical (CVSS 8.8). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-dashboard-rhel9:1786109665, rhoai/odh-dashboard-rhel9:1785940823, rhoai/odh-dashboard-rhel9:1786109683. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.

CVE-2026-18950
Unclassified
Aug 10, 2026
High8.8Vendor: CriticalRed Hat

High [CVE-2026-18949] ClusterRole grants cluster-wide CRUD on secrets and RBAC management resources

ClusterRole grants cluster-wide CRUD on secrets and RBAC management resources. Red Hat rates this critical (CVSS 8.8). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-dashboard-rhel9:1786109665, rhoai/odh-dashboard-rhel9:1785940823, rhoai/odh-dashboard-rhel9:1786109683. Affected products named by the advisory: Red Hat OpenShift AI 3.3; Red Hat OpenShift AI (RHOAI).

CVE-2026-18949
Unclassified
Aug 10, 2026
High8.5Red Hat

High [CVE-2026-18947] Authorization bypass in /materialize endpoints enables DoS via unauthorized full re-materialization

Authorization bypass in /materialize endpoints enables DoS via unauthorized full re-materialization. Red Hat rates this important (CVSS 8.5). Red Hat lists fixing advisory RHSA-2026:53263 with package rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786110033. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3.

CVE-2026-18947
Unclassified
Aug 10, 2026