Skip to content
VulniPulse
Highest advisory severityHigh 2 vendors · 2 advisories

CVE-2026-76038

CVE-2026-76038: 2 tracked advisory records across Palo Alto, Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Palo Alto

1 advisory
  • Advisory severityHigh

    High [CVE-2026-76020 +18] PAN-SA-2026-0012 Chromium: Monthly Vulnerability Update (September 2026)

    PAN-SA-2026-0012Source published

    This bulletin covers 19 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.

    PAN-SA-2026-0012 Chromium: Monthly Vulnerability Update (September 2026)

    Affected products in this advisory
    No product details extracted. Check the source bulletin.
    Source-reported affected versions
    • Prisma Browser < 151.26.5.170
    Source-reported fixed versions
    • Prisma Browser >= 152.8.4.76
    Mitigation guidance
    • Upgrade to a fixed release: Prisma Browser >= 152.8.4.76.
    Workarounds
    • No known workarounds exist for this issue.

Red Hat

1 advisory
  • Advisory severityHigh8.8

    High [CVE-2026-76038] Remote code execution via type confusion in crafted HTML.

    CVE-2026-76038Source published Source updated

    Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High) A flaw was found in V8, the open-source JavaScript engine used in Google Chrome. Exploitation occurs when a user visits a specially crafted HTML page, leading to potential compromise of the affected system. This vulnerability is rated as Important. A type confusion flaw in the V8 JavaScript engine can lead to remote code execution when processing a specially crafted HTML page. Exploitation requires user interaction, as an attacker must entice a user to visit a malicious website. This primarily impacts desktop environments and applications that render untrusted web content, such as Chromium and…

    Affected products in this advisory
    No product details extracted. Check the source bulletin.
    Source-reported affected versions
    • < 151.0.7922.169
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    • To mitigate this vulnerability, users should avoid opening untrusted web content or visiting untrusted websites. For systems where web browsing functionality is not required, consider removing packages that provide web rendering capabilities, such as `chromium` or `qt5-qtwebengine`/`qt6-qtwebengine`. Note that removing these packages may impact the functionality of other desktop applications or the desktop environment itself.

Android app · Google Play

Turn CVE research into alerts on your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery