CYBERSECURITYTRACKER
TRACKING7,183 stories in this site build1,510 vulnerability news stories in this site build
Vulnerabilities

March 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 0 vulnerabilities with exploitation detected in the wild this month. This defender-focused view covers 1,069 vulnerabilities across 3,314 returned patch records from 4 vendors. Filter the complete month, or browse the static page trail without JavaScript.

3,314all patch recordsClear filters78criticalShow these records0Microsoft exploitation detectedShow these records2Microsoft in the Known Exploited Vulnerabilities catalogShow these records202tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 1 of 17 · records 1 to 200 of 3,314

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-3909 ↗Microsoft Edge (Chromium-based)N/AOut-of-band2%Microsoft rating unavailableCISA KEVVulnCheckENISA1 mentionsChromium: CVE-2026-3909 Out of bounds write in Skia
CVE-2026-3910 ↗Microsoft Edge (Chromium-based)N/AOut-of-band2%Microsoft rating unavailableCISA KEVVulnCheckENISA1 mentionsChromium: CVE-2026-3910 Inappropriate implementation in V8
CVE-2026-23658 ↗Azure DevOps: msazureCriticalOut-of-band1%Microsoft rates: N/AAzure DevOps: msazure Elevation of Privilege Vulnerability
CVE-2026-23659 ↗Azure Data FactoryCriticalOut-of-band1%Microsoft rates: N/AAzure Data Factory Information Disclosure Vulnerability
CVE-2026-24299 ↗Microsoft 365 CopilotCriticalOut-of-band1%Microsoft rates: N/AM365 Copilot Information Disclosure Vulnerability
CVE-2026-26120 ↗Microsoft BingCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Bing Tampering Vulnerability
CVE-2026-26136 ↗Microsoft CopilotCriticalOut-of-band1%Microsoft rating unavailableMicrosoft Copilot Information Disclosure Vulnerability
CVE-2026-26137 ↗Microsoft Exchange OnlineCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Exchange Elevation of Privilege Vulnerability
CVE-2026-26138 ↗Microsoft PurviewCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Purview Elevation of Privilege Vulnerability
CVE-2026-26139 ↗Microsoft PurviewCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Purview Elevation of Privilege Vulnerability
CVE-2026-32169 ↗Azure Cloud ShellCriticalOut-of-band1%Microsoft rates: N/AAzure Cloud Shell Elevation of Privilege Vulnerability
CVE-2026-32191 ↗Microsoft Bing ImagesCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Bing Images Remote Code Execution Vulnerability
CVE-2026-32194 ↗Microsoft Bing ImagesCriticalOut-of-band1%Microsoft rates: N/A1 mentionsMicrosoft Bing Images Remote Code Execution Vulnerability
CVE-2026-26110 ↗Microsoft Office 2019 for 32-bit editionsCritical0%Microsoft rates: Exploitation Less LikelyKB50028381 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-26113 ↗Microsoft SharePoint Enterprise Server 2016Critical1%Microsoft rates: Exploitation Less LikelyKB5002843KB5002845
and 4 moreKB5002847KB5002848KB5002850KB5002851
1 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-26144 ↗Microsoft 365 Apps for Enterprise for 64-bit SystemsCritical1%Microsoft rates: Exploitation Unlikely1 mentionsMicrosoft Excel Information Disclosure Vulnerability
CVE-2026-21536 ↗Microsoft Devices Pricing ProgramCriticalOut-of-band2%Microsoft rates: Exploitation UnlikelyMicrosoft Devices Pricing Program Remote Code Execution Vulnerability
CVE-2026-23651 ↗Microsoft ACI Confidential ContainersCriticalOut-of-band1%Microsoft rates: Exploitation Less LikelyMicrosoft ACI Confidential Containers Elevation of Privilege Vulnerability
CVE-2026-26122 ↗Microsoft ACI Confidential ContainersCriticalOut-of-band1%Microsoft rates: Exploitation Less LikelyMicrosoft ACI Confidential Containers Information Disclosure Vulnerability
CVE-2026-26124 ↗Microsoft ACI Confidential ContainersCriticalOut-of-band0%Microsoft rates: Exploitation Less LikelyMicrosoft ACI Confidential Containers Elevation of Privilege Vulnerability
CVE-2026-26125 ↗Payment Orchestrator ServiceCriticalOut-of-band1%Microsoft rates: N/APayment Orchestrator Service Elevation of Privilege Vulnerability
CVE-2026-4739 ↗cbl2 cmake 3.21.4-23 on CBL Mariner 2.0CriticalOut-of-bandNot availableMicrosoft rating unavailableInteger overflow vulnerabilities in InsightSoftwareConsortium/ITK
CVE-2026-4176 ↗cbl2 boost 1.76.0-4 on CBL Mariner 2.0CriticalOut-of-bandNot availableMicrosoft rating unavailablePerl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib
CVE-2026-33937 ↗cbl2 reaper 3.1.1-22 on CBL Mariner 2.0CriticalOut-of-bandNot availableMicrosoft rating unavailableHandlebars.js has JavaScript Injection via AST Type Confusion
CVE-2026-4746 ↗cbl2 cloud-hypervisor 32.0-7 on CBL Mariner 2.0CriticalOut-of-bandNot availableMicrosoft rating unavailableHeap Buffer Over-Write Vulenrabilty in timeplus-io/proton
CVE-2026-23395 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableBluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ
CVE-2025-69720 ↗azl3 ncurses 6.4-2 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableThe infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.
CVE-2026-3381 ↗cbl2 cloud-hypervisor 32.0-7 on CBL Mariner 2.0CriticalOut-of-bandNot availableMicrosoft rating unavailableCompress::Raw::Zlib versions through 2.219 for Perl use potentially insecure versions of zlib
CVE-2026-21710 ↗cbl2 nodejs18 18.20.3-12ImportantOut-of-band25%Microsoft rating unavailableA flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a non-array. This exception is thrown synchronously inside a property getter and cannot be intercepted by `error` event listeners, meaning it cannot be handled without wrapping every `req.headersDistinct` access in a `try/catch`. * This vulnerability affects all Node.js HTTP servers on **20.x, 22.x, 24.x, and v25.x**
CVE-2026-26133 ↗Microsoft OneNote for iOSImportantOut-of-band0%Microsoft rates: Exploitation Less LikelyM365 Copilot Information Disclosure Vulnerability
CVE-2026-20967 ↗System Center Operations Manager 2019Important1%Microsoft rates: Exploitation Less LikelySystem Center Operations Manager (SCOM) Elevation of Privilege Vulnerability
CVE-2026-21262 ↗Microsoft SQL Server 2017 for x64-based Systems (GDR)Important2%Microsoft rates: Exploitation Less LikelyPublicly disclosedVulnCheckKB5077464KB5077465
and 8 moreKB5077466KB5077468KB5077469KB5077470KB5077471KB5077472KB5077473KB5077474
1 mentionsSQL Server Elevation of Privilege Vulnerability
CVE-2026-23654 ↗GitHub Repo: Zero Shot scFoundationImportant1%Microsoft rates: Exploitation UnlikelyGitHub: Zero Shot SCFoundation Remote Code Execution Vulnerability
CVE-2026-23656 ↗Windows App Client for Windows DesktopImportant0%Microsoft rates: Exploitation UnlikelyWindows App Installer Spoofing Vulnerability
CVE-2026-23660 ↗Windows Admin Center in Azure PortalImportant0%Microsoft rates: Exploitation Less LikelyWindows Admin Center in Azure Portal Elevation of Privilege Vulnerability
CVE-2026-23661 ↗Azure IoT ExplorerImportant1%Microsoft rates: Exploitation Less LikelyAzure IoT Explorer Information Disclosure Vulnerability
CVE-2026-23662 ↗Azure IoT ExplorerImportant1%Microsoft rates: Exploitation Less LikelyAzure IoT Explorer Information Disclosure Vulnerability
CVE-2026-23664 ↗Azure IoT ExplorerImportant1%Microsoft rates: Exploitation Less LikelyAzure IoT Explorer Information Disclosure Vulnerability
CVE-2026-23667 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5078752KB5078883
and 4 moreKB5078885KB5079420KB5079466KB5079473
Broadcast DVR Elevation of Privilege Vulnerability
CVE-2026-23668 ↗Windows 10 Version 1809 for 32-bit SystemsImportant4%Microsoft rates: Exploitation More LikelyKB5078734KB5078737
and 7 moreKB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2026-23669 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
RPC Runtime Library Remote Code Execution Vulnerability
CVE-2026-23671 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 10 moreKB5078737KB5078740KB5078752KB5078766KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Bluetooth RFCOM Protocol Driver Elevation of Privilege Vulnerability
CVE-2026-23672 ↗Windows Server 2022 (Server Core installation)Important0%Microsoft rates: Exploitation UnlikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
CVE-2026-23673 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVE-2026-23674 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5078734KB5078736
and 13 moreKB5078737KB5078738KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
MapUrlToZone Security Feature Bypass Vulnerability
CVE-2026-24282 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5078752KB5078883
and 5 moreKB5078885KB5078938KB5079420KB5079466KB5079473
Push message Routing Service Elevation of Privilege Vulnerability
CVE-2026-24283 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 4 moreKB5078740KB5079420KB5079466KB5079473
Multiple UNC Provider Kernel Driver Elevation of Privilege Vulnerability
CVE-2026-24285 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 11 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079473
Win32k Elevation of Privilege Vulnerability
CVE-2026-24287 ↗Windows Server 2022Important0%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 9 moreKB5078737KB5078740KB5078752KB5078766KB5078883KB5078885KB5079420KB5079466KB5079473
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-24288 ↗Windows 10 Version 21H2 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5078885Windows Mobile Broadband Driver Remote Code Execution Vulnerability
CVE-2026-24289 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant4%Microsoft rates: Exploitation More LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-24290 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 9 moreKB5078737KB5078740KB5078752KB5078766KB5078883KB5078885KB5079420KB5079466KB5079473
Windows Projected File System Elevation of Privilege Vulnerability
CVE-2026-24291 ↗Windows 10 Version 1809 for 32-bit SystemsImportant3%Microsoft rates: Exploitation More LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege Vulnerability
CVE-2026-24292 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 9 moreKB5078737KB5078740KB5078752KB5078766KB5078883KB5078885KB5079420KB5079466KB5079473
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2026-24293 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 8 moreKB5078737KB5078740KB5078766KB5078883KB5078885KB5079420KB5079466KB5079473
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-24294 ↗Windows 10 Version 1809 for 32-bit SystemsImportant5%Microsoft rates: Exploitation More LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-24295 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 10 moreKB5078737KB5078740KB5078752KB5078766KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-24296 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5078734KB5078736
and 11 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Device Association Service Elevation of Privilege Vulnerability
CVE-2026-24297 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5078752KB5078774
and 3 moreKB5078775KB5078885KB5078938
Windows Kerberos Security Feature Bypass Vulnerability
CVE-2026-25165 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Performance Counters for Windows Elevation of Privilege Vulnerability
CVE-2026-25166 ↗Windows ADK for Windows 11, version 24H2Important2%Microsoft rates: Exploitation UnlikelyWindows System Image Manager Assessment and Deployment Kit (ADK) Remote Code Execution Vulnerability
CVE-2026-25167 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5078736KB5078740
and 3 moreKB5079420KB5079466KB5079473
Microsoft Brokering File System Elevation of Privilege Vulnerability
CVE-2026-25168 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Graphics Component Denial of Service Vulnerability
CVE-2026-25169 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Graphics Component Denial of Service Vulnerability
CVE-2026-25170 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 7 moreKB5078737KB5078740KB5078766KB5078883KB5079420KB5079466KB5079473
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2026-25171 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Authentication Elevation of Privilege Vulnerability
CVE-2026-25172 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079466KB5079473KB5084597
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2026-25173 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079466KB5079473KB5084597
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2026-25174 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation UnlikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Extensible File Allocation Table Elevation of Privilege Vulnerability
CVE-2026-25175 ↗Windows Server 2022 (Server Core installation)Important0%Microsoft rates: Exploitation Less LikelyKB5078734KB5078737
and 7 moreKB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938
Windows NTFS Elevation of Privilege Vulnerability
CVE-2026-25176 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-25177 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2026-25178 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-25179 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
CVE-2026-25180 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Graphics Component Information Disclosure Vulnerability
CVE-2026-25181 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
GDI+ Information Disclosure Vulnerability
CVE-2026-25185 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Shell Link Processing Spoofing Vulnerability
CVE-2026-25186 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Accessibility Infrastructure (ATBroker.exe) Information Disclosure Vulnerability
CVE-2026-25187 ↗Windows 10 Version 1809 for 32-bit SystemsImportant3%Microsoft rates: Exploitation More LikelyVulnCheckKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
1 mentionsWinlogon Elevation of Privilege Vulnerability
CVE-2026-25188 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant1%Microsoft rates: Exploitation UnlikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows Telephony Service Elevation of Privilege Vulnerability
CVE-2026-25189 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5078737KB5078752
and 2 moreKB5078766KB5078885
Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2026-25190 ↗Windows 11 Version 26H1 for ARM64-based SystemsImportant0%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows GDI Remote Code Execution Vulnerability
CVE-2026-26030 ↗Microsoft Semantic Kernel Python SDKImportant4%Microsoft rates: Exploitation UnlikelyGitHub: CVE-2026-26030 Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable
CVE-2026-26105 ↗Microsoft SharePoint Enterprise Server 2016Important1%Microsoft rates: Exploitation Less LikelyKB5002843KB5002845
and 1 moreKB5002850
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2026-26106 ↗Microsoft SharePoint Enterprise Server 2016Important1%Microsoft rates: Exploitation Less LikelyKB5002843KB5002845
and 1 moreKB5002850
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-26107 ↗Office Online ServerImportant0%Microsoft rates: Exploitation Less LikelyKB5002846KB5002849Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-26108 ↗Office Online ServerImportant0%Microsoft rates: Exploitation Less LikelyKB5002718KB5002846
and 1 moreKB5002849
Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-26109 ↗Office Online ServerImportant0%Microsoft rates: Exploitation UnlikelyKB5002846KB5002849Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-26111 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079466KB5079473KB5084597
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2026-26112 ↗Office Online ServerImportant0%Microsoft rates: Exploitation Less LikelyKB5002846KB5002849Microsoft Excel Remote Code Execution Vulnerability
CVE-2026-26114 ↗Microsoft SharePoint Enterprise Server 2016Important3%Microsoft rates: Exploitation Less LikelyKB5002845KB5002850Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-26115 ↗Microsoft SQL Server 2025 for x64-based Systems (GDR)Important1%Microsoft rates: Exploitation Less LikelyKB5077464KB5077465
and 8 moreKB5077466KB5077468KB5077469KB5077470KB5077471KB5077472KB5077473KB5077474
SQL Server Elevation of Privilege Vulnerability
CVE-2026-26116 ↗Microsoft SQL Server 2025 for x64-based Systems (GDR)Important1%Microsoft rates: Exploitation Less LikelyKB5077466KB5077468SQL Server Elevation of Privilege Vulnerability
CVE-2026-26117 ↗Arc Enabled Servers - Azure Connected Machine AgentImportant0%Microsoft rates: Exploitation UnlikelyArc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability
CVE-2026-26118 ↗Azure MCP Server Tools 2.0.0 (NuGet)Important1%Microsoft rates: Exploitation Less LikelyAzure MCP Server Tools Elevation of Privilege Vulnerability
CVE-2026-26121 ↗Azure IoT ExplorerImportant1%Microsoft rates: Exploitation Less LikelyAzure IOT Explorer Spoofing Vulnerability
CVE-2026-26123 ↗Microsoft Authenticator for AndroidImportant1%Microsoft rates: Exploitation Less LikelyMicrosoft Authenticator Information Disclosure Vulnerability
CVE-2026-26127 ↗Microsoft.Bcl.Memory 10.0Important2%Microsoft rates: Exploitation UnlikelyPublicly disclosedVulnCheckKB5081276KB50812781 mentions.NET Denial of Service Vulnerability
CVE-2026-26128 ↗Windows 10 Version 1809 for 32-bit SystemsImportant1%Microsoft rates: Exploitation Less LikelyKB5078734KB5078736
and 12 moreKB5078737KB5078740KB5078752KB5078766KB5078774KB5078775KB5078883KB5078885KB5078938KB5079420KB5079466KB5079473
Windows SMB Server Elevation of Privilege Vulnerability
CVE-2026-26130 ↗ASP.NET Core 8.0Important3%Microsoft rates: Exploitation Less LikelyKB5081276KB5081277
and 1 moreKB5081278
ASP.NET Core Denial of Service Vulnerability
CVE-2026-26131 ↗.NET 10.0 installed on LinuxImportant0%Microsoft rates: Exploitation Less LikelyKB5081276.NET Elevation of Privilege Vulnerability
CVE-2026-26132 ↗Windows Server 2022Important2%Microsoft rates: Exploitation More LikelyKB5078734KB5078736
and 8 moreKB5078737KB5078740KB5078766KB5078883KB5078885KB5079420KB5079466KB5079473
Windows Kernel Elevation of Privilege Vulnerability
CVE-2026-26134 ↗Microsoft Office for AndroidImportant0%Microsoft rates: Exploitation Less LikelyMicrosoft Office Elevation of Privilege Vulnerability
CVE-2026-26141 ↗Azure Automation Hybrid Worker Windows ExtensionImportant0%Microsoft rates: Exploitation UnlikelyHybrid Worker Extension (Arc‑enabled Windows VMs) Elevation of Privilege Vulnerability
CVE-2026-26148 ↗Microsoft Azure AD SSH Login extension for LinuxImportant0%Microsoft rates: Exploitation UnlikelyMicrosoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability
CVE-2026-32597 ↗azl3 python-jwt 2.8.0-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablePyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)
CVE-2026-31788 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablexen/privcmd: restrict usage in unprivileged domU
CVE-2025-70873 ↗azl3 sqlite 3.44.0-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableAn information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.
CVE-2026-32287 ↗cbl2 telegraf 1.29.4-22 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableInfinite loop in github.com/antchfx/xpath
CVE-2026-29785 ↗cbl2 telegraf 1.29.4-22 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableNATS Server panic via malicious compression on leafnode port
CVE-2026-33216 ↗cbl2 telegraf 1.29.4-22 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableNATS has MQTT plaintext password disclosure
CVE-2026-4732 ↗azl3 libsndfile 1.2.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableOut-of-bounds Read Overflow in tildearrow/furnace
CVE-2026-5121 ↗cbl2 libarchive 3.6.1-9 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableLibarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing
CVE-2026-5201 ↗cbl2 gdk-pixbuf2 2.40.0-8 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableGdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image
CVE-2026-33554 ↗cbl2 freeipmi 1.6.6-3 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableipmi-oem in FreeIPMI before 1.16.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Three subcommands were found to have exploitable buffer overflows on response messages. They are: "ipmi-oem dell get-last-post-code - get the last POST code and string describing the error on some Dell servers," "ipmi-oem supermicro extra-firmware-info - get extra firmware info on Supermic
CVE-2026-4046 ↗cbl2 glibc 2.35-10 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableiconv crash due to assertion failure with untrusted input
CVE-2026-34714 ↗cbl2 vim 9.2.0240-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableVim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.
CVE-2026-33940 ↗cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableHandlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
CVE-2026-33939 ↗cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableHandlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
CVE-2026-33941 ↗cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableHandlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
CVE-2026-33938 ↗cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableHandlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
CVE-2026-33891 ↗cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableForge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
CVE-2026-33896 ↗azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableForge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
CiscoCVE-2026-20079trackedCVSS 10.0Cisco Secure Firewall Management Center (FMC) Appliances7.0Patch ↗Advisory ↗
CiscoCVE-2026-20131trackedCVSS 10.0Cisco Secure Firewall Management Center (FMC) Appliances7.0Patch ↗Advisory ↗
Red HatCVE-2026-1615CVSS 9.8Red Hat Ansible Automation Platform 2.5registry.redhat.io/ansible-automation-platform-25/lightspeed-rhel8@sha256:0682e9e4bc9ad2b2b564fa2fa8b022e46729b27e26ec7b14ed2f1fae3e52a0d1_s390xPatch ↗Advisory ↗
Red HatCVE-2026-1615CVSS 9.8Red Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform-26/lightspeed-rhel9@sha256:293b2d26b9a82fa6a55dafb4c594287838cae765c358f3bdfea5b89d83f0391e_s390xPatch ↗Advisory ↗
Red HatCVE-2026-28498CVSS 9.1Red Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform-26/lightspeed-chatbot-rhel9@sha256:111c3fa869282760a7408db240e5fbddd74816fa5ffc12578c267427eae8eb96_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-28802CVSS 9.1Red Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform-26/lightspeed-chatbot-rhel9@sha256:111c3fa869282760a7408db240e5fbddd74816fa5ffc12578c267427eae8eb96_ppc64lePatch ↗Advisory ↗
Red HatCVE-2024-3884Critical (Red Hat rating)Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Servereap7-undertow-0:2.0.41-7.SP8_redhat_00001.1.el7eap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-24046CVSS 9.1Red Hat Developer Hub 1.8registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:2e8ed97c6e6d232f66bb81dc074b8bb2712dc54004cc565fcb1d2b43a9bb2046_amd64Patch ↗Advisory ↗
Red HatCVE-2026-27606CVSS 9.1Red Hat Developer Hub 1.8registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:2e8ed97c6e6d232f66bb81dc074b8bb2712dc54004cc565fcb1d2b43a9bb2046_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Developer Hub 1.8registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:72d72d0e8b67012bfaaeae0e1fbbcf8e35c74d4d6252051eabef3e9dd979d48e_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33211CVSS 9.6Red Hat OpenShift Pipelines 1.21registry.redhat.io/openshift-pipelines/pipelines-resolvers-rhel9@sha256:0eeefa13b3b9d1a03e25ec2e3e413bcd3d6d321a6acca853d6201f8943a62894_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33211CVSS 9.6Red Hat OpenShift Pipelines 1.21registry.redhat.io/openshift-pipelines/pipelines-operator-bundle@sha256:6585794d76cffb3f87fc7eacb905f0dd5f02476f717c911f2c0faf7c4081a080_amd64Patch ↗Advisory ↗
Red HatCVE-2026-22797CVSS 9.9Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/ose-ironic-rhel9@sha256:5790d9114681ad940a65723e23bed39b2f5eac1dbde017f368861222058064e8_arm64Patch ↗Advisory ↗
Red HatCVE-2026-27606CVSS 9.1Red Hat Trusted Artifact Signer 1.3registry.redhat.io/rhtas/rhtas-console-ui-rhel9@sha256:d23bf73126fb5c18ff24369bb05c7adb03e9f3fefdbb49795b8aeb3d7c223cdb_amd64Patch ↗Advisory ↗
Red HatCVE-2026-27606CVSS 9.1Red Hat Quay 3.1registry.redhat.io/quay/quay-rhel8@sha256:6e13793ca8f309ec0b69ae609b840ff0f41989d88cd4bba127e1b0040631367e_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-27962CVSS 9.1Red Hat Quay 3.1registry.redhat.io/quay/quay-rhel8@sha256:6e13793ca8f309ec0b69ae609b840ff0f41989d88cd4bba127e1b0040631367e_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-28802CVSS 9.1Red Hat Quay 3.1registry.redhat.io/quay/quay-rhel8@sha256:6e13793ca8f309ec0b69ae609b840ff0f41989d88cd4bba127e1b0040631367e_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-15467CVSS 9.8Red Hat OpenShift Container Platform 4.15rhcos-aarch64-415.92.202603101737-0Patch ↗Advisory ↗
Red HatCVE-2026-27606CVSS 9.1Red Hat OpenShift Service Mesh 2.6registry.redhat.io/openshift-service-mesh/kiali-rhel8@sha256:5a8a46e92a178be088251e0dcb67612d16bafeee910af6bd55de82a4727daa02_amd64Patch ↗Advisory ↗
Red HatCVE-2026-28802CVSS 9.1Red Hat Quay 3.9registry.redhat.io/quay/quay-rhel8@sha256:3e5ce0a56241c9804249dfb302cde02d2ffe30ba8fcd8aef8f1bce916d2324ad_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-12543CVSS 9.6Red Hat JBoss EAP 7.4 ELS for RHEL 7 Servereap7-undertow-0:2.2.39-1.Final_redhat_00001.1.el7eap.noarchPatch ↗Advisory ↗
Red HatCVE-2025-12543CVSS 9.6Red Hat JBoss EAP 7.4 ELS for RHEL 8eap7-undertow-0:2.2.39-1.Final_redhat_00001.1.el8eap.noarchPatch ↗Advisory ↗
Red HatCVE-2025-12543CVSS 9.6Red Hat JBoss EAP 7.4 ELS for RHEL 9eap7-undertow-0:2.2.39-1.Final_redhat_00001.1.el9eap.noarchPatch ↗Advisory ↗
Red HatCVE-2025-12543CVSS 9.6Red Hat JBoss Enterprise Application Platform 7.4.24io.undertow.undertow-core-2.2.39.Final-redhat-00001.jarPatch ↗Advisory ↗
Red HatCVE-2025-15467CVSS 9.8Red Hat Update Infrastructure 5registry.redhat.io/rhui5/cds-rhel9@sha256:200c27e9b396276bd505c6b41127ac5eb1d94d620172cb818ae733f2a21ac524_amd64Patch ↗Advisory ↗
Red HatCVE-2026-22797CVSS 9.9Red Hat OpenShift Container Platform 4.19registry.redhat.io/openshift4/ose-ironic-rhel9@sha256:64f69dda395c7912c23def5367853f2f34ad32581a76785202d864ae99c56219_arm64Patch ↗Advisory ↗
Red HatCVE-2026-28802CVSS 9.1Red Hat Quay 3.12registry.redhat.io/quay/quay-rhel8@sha256:2f62df99c2b7697461a2865380344c90a6fb8aec7b279f8f2f6e0684b662d19f_amd64Patch ↗Advisory ↗
Red HatCVE-2026-22797CVSS 9.9Red Hat OpenShift Container Platform 4.20registry.redhat.io/openshift4/ose-ironic-rhel9@sha256:7e57a906f55fdc4522dd130c76942999c5c28f469579dcdda2e78949a860b8f8_arm64Patch ↗Advisory ↗
Red HatCVE-2026-27446CVSS 9.1Red Hat AMQ Broker 7.13.4Not reportedPatch ↗Advisory ↗
AndroidCVE-2024-43859Critical (Android rating):linux_kernel:Not reportedPatch ↗Advisory ↗
Red HatCVE-2025-12543CVSS 9.6Red Hat JBoss EAP 8.0 for RHEL 8eap8-bouncycastle-0:1.83.0-1.redhat_00001.1.el8eap.noarchPatch ↗Advisory ↗
Red HatCVE-2025-12543CVSS 9.6Red Hat build of Apache Camel 4.14.4 for Spring Boot 3.5.11Not reportedPatch ↗Advisory ↗
Red HatCVE-2025-12543CVSS 9.6Red Hat JBoss EAP 8.0 for RHEL 9eap8-bouncycastle-0:1.83.0-1.redhat_00001.1.el9eap.noarchPatch ↗Advisory ↗
Red HatCVE-2025-12543CVSS 9.6Red Hat JBoss Enterprise Application Platform 8.0Not reportedPatch ↗Advisory ↗
Red HatCVE-2025-15467CVSS 9.8Red Hat OpenShift Container Platform 4.13rhcos-x86_64-413.92.202602240113-0Patch ↗Advisory ↗
AndroidCVE-2026-0027Critical (Android rating):linux_kernel:Not reportedPatch ↗Advisory ↗
AndroidCVE-2026-0028Critical (Android rating):linux_kernel:Not reportedPatch ↗Advisory ↗
AndroidCVE-2026-0030Critical (Android rating):linux_kernel:Not reportedPatch ↗Advisory ↗
AndroidCVE-2026-0031Critical (Android rating):linux_kernel:Not reportedPatch ↗Advisory ↗
AndroidCVE-2026-0037Critical (Android rating):linux_kernel:Not reportedPatch ↗Advisory ↗
AndroidCVE-2026-0038Critical (Android rating):linux_kernel:Not reportedPatch ↗Advisory ↗
AndroidCVE-2026-0114Critical (Android rating)Not reportedNot reportedno patch linkAdvisory ↗
AndroidCVE-2026-0120Critical (Android rating)Not reportedNot reportedno patch linkAdvisory ↗
AndroidCVE-2026-0122Critical (Android rating)Not reportedNot reportedno patch linkAdvisory ↗
AndroidCVE-2026-0124Critical (Android rating)Not reportedNot reportedno patch linkAdvisory ↗
Red HatCVE-2026-27446CVSS 9.1Red Hat AMQ Broker 7.12.6Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-22778CVSS 9.8Red Hat OpenShift AI 3.3registry.redhat.io/rhoai/odh-vllm-gaudi-rhel9@sha256:30dd95f0c900b81b80e435796d82dd556814dd6d46c6b43b7dd879bcfdb8420e_amd64Patch ↗Advisory ↗
Red HatCVE-2026-22778CVSS 9.8Red Hat OpenShift AI 2.25registry.redhat.io/rhoai/odh-vllm-cpu-rhel9@sha256:10ea60405654199ff5d09b50fc8b83f6d9bb9dda8057e18441dead800b8fa974_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-22797CVSS 9.9Red Hat OpenShift Container Platform 4.21registry.redhat.io/openshift4/ose-ironic-rhel9@sha256:1d1766c76d70f3378b45f9065e5576251f3fee3d56ee379a9c55af86e1e70c44_arm64Patch ↗Advisory ↗
AndroidCVE-2025-48631Critical (Android rating)platform/frameworks/baseNot reportedPatch ↗Advisory ↗
AndroidCVE-2026-0006Critical (Android rating)platform/external/libopenapvNot reportedPatch ↗Advisory ↗
AndroidCVE-2026-0047Critical (Android rating)platform/frameworks/baseNot reportedPatch ↗Advisory ↗
Red HatCVE-2026-1207trackedCVSS 8.3Red Hat Satellite 6.18registry.redhat.io/satellite/iop-advisor-backend-rhel9@sha256:563d17f7250c9a5ccb9f7213332b0a8e0b876e8e4e9814a7f397e51972c60a2c_amd64Patch ↗Advisory ↗
Red HatCVE-2026-1207trackedCVSS 8.3Red Hat Satellite 6.17 for RHEL 9foreman-0:3.14.0.14-1.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-1207trackedCVSS 8.3Red Hat Satellite 6.16 for RHEL 8python-django-0:4.2.28-0.1.el8pc.srcPatch ↗Advisory ↗
Red HatCVE-2026-26127trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)aspnetcore-runtime-9.0-0:9.0.14-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-26127trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)aspnetcore-runtime-10.0-0:10.0.4-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-26127trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 10)aspnetcore-runtime-9.0-0:9.0.14-1.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-26127trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 10)aspnetcore-runtime-10.0-0:10.0.4-1.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-26127trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)aspnetcore-runtime-9.0-0:9.0.14-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-26127trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)aspnetcore-runtime-10.0-0:10.0.4-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-26130trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)aspnetcore-runtime-9.0-0:9.0.14-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-26130trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)aspnetcore-runtime-10.0-0:10.0.4-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-26130trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 10)aspnetcore-runtime-9.0-0:9.0.14-1.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-26130trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 10)aspnetcore-runtime-8.0-0:8.0.25-1.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-26130trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 10)aspnetcore-runtime-10.0-0:10.0.4-1.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-26130trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)aspnetcore-runtime-8.0-0:8.0.25-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-26130trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)aspnetcore-runtime-8.0-0:8.0.25-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-26130trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)aspnetcore-runtime-9.0-0:9.0.14-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-26130trackedCVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)aspnetcore-runtime-10.0-0:10.0.4-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-1207trackedCVSS 8.3Red Hat Ansible Automation Platform 2.6 for RHEL 9python3.12-django-0:4.2.28-1.el9ap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-1207trackedCVSS 8.3Red Hat Ansible Automation Platform 2.5 for RHEL 8python3.12-django-0:4.2.28-1.el8ap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-1207trackedCVSS 8.3Red Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform-26/lightspeed-rhel9@sha256:0b6086acb5dc2c46ba74583bbe1b39f22317a386fa4b89b6f592dfe6e9e10511_arm64Patch ↗Advisory ↗
Red HatCVE-2026-1207trackedCVSS 8.3Red Hat Ansible Automation Platform 2.5registry.redhat.io/ansible-automation-platform-25/lightspeed-rhel8@sha256:069c671a4745f1059e48d1813e593fc33665d9c4c1e0b14c12a0ca3bc8d32080_s390xPatch ↗Advisory ↗
AndroidCVE-2025-39682trackedHigh (Android rating):linux_kernel:Not reportedPatch ↗Advisory ↗
AndroidCVE-2026-21385trackedHigh (Android rating):linux_kernel:QualcommNot reportedPatch ↗Advisory ↗
Red HatCVE-2025-62593trackedCVSS 8.8Red Hat OpenShift AI 3.3registry.redhat.io/rhoai/odh-vllm-gaudi-rhel9@sha256:30dd95f0c900b81b80e435796d82dd556814dd6d46c6b43b7dd879bcfdb8420e_amd64Patch ↗Advisory ↗

Glossary