Complete feed
Security advisories & CVEs
1929 advisories across 32 monitored vendors.
Android app · Google Play
Take your CVE monitoring with you.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Medium [CVE-2026-68743] PAM responder out-of-bounds read via unchecked auth_token_length in protocol v1
PAM responder out-of-bounds read via unchecked auth_token_length in protocol v1. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more.
Medium [CVE-2026-12259] Installation of attacker-controlled packages due to improper checksum validation
Installation of attacker-controlled packages due to improper checksum validation. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-354. Affected products named by the advisory: Exploit Intelligence; Lightspeed Core; OpenShift Lightspeed; Red Hat Ansible Automation Platform 2; and 1 more. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI).
Medium [CVE-2026-6695] remote code execution via crafted paa file
A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer. This could lead to heap metadata corruption and potentially enable the attacker to execute arbitrary code on the affected system. Red Hat Enterprise Linux systems where GIMP is installed and used to process untrusted image files are affected. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-805. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-6694] gimp file-png plugin: denial of service via oversized apng trns chunk
A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. When processing a specially crafted APNG image, the plugin may crash due to a stack buffer overflow. As GIMP executes plugins in separate processes, the main application remains unaffected, limiting the impact to the plugin's functionality. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-59652] LDAP filter injection in legacy jdk1.4 LDAPStoreHelper
LDAP filter injection in legacy jdk1.4 LDAPStoreHelper. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-90.
Medium [CVE-2026-18573] Client access-type policy condition bypass during client update
Client access-type policy condition bypass during client update. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-862. Affected product named by the advisory: Red Hat Build of Keycloak.
Medium [CVE-2026-18572] UMA claim token can override authorization time-policy evaluation attributes
UMA claim token can override authorization time-policy evaluation attributes. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-863. Affected product named by the advisory: Red Hat Build of Keycloak.
Medium [CVE-2026-18571] FGAP V2 group assignment bypass during user creation
FGAP V2 group assignment bypass during user creation. Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-862.
Medium [CVE-2026-18570] Full-scope-disabled client policy validation bypass via omitted fullScopeAllowed
Full-scope-disabled client policy validation bypass via omitted fullScopeAllowed. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-862. Affected product named by the advisory: Red Hat Build of Keycloak.