CYBERSECURITYTRACKER
TRACKING3,612 stories653 vuln stories
Patch Day month

March 2026 vulnerabilities

A server-rendered hunting trail for March 2026: 1,512 returned patch records across 4 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.

1,512all patches
60critical
0exploitation detected
2in CISA KEV
181tracked here
Red Hat 859Microsoft 460Android 136Cisco 57

Page 1 of 8 · records 1–200 of 1,512

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-4948 ↗2026-05-02cbl2 firewalld 1.0.3-2 on CBL Mariner 2.0ModerateOut-of-bandFirewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
CVE-2026-23362 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandcan: bcm: fix locking for bcm_op runtime updates
CVE-2026-23394 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandaf_unix: Give up GC if MSG_PEEK intervened.
CVE-2026-23360 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnvme: fix admin queue leak on controller reset
CVE-2026-31788 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandxen/privcmd: restrict usage in unprivileged domU
CVE-2025-70873 ↗2026-04-18azl3 sqlite 3.44.0-2 on Azure Linux 3.0ImportantOut-of-bandAn information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.
CVE-2026-0968 ↗2026-04-05azl3 libssh 0.10.6-6 on Azure Linux 3.0LowOut-of-bandLibssh: libssh: denial of service due to malformed sftp message
CVE-2026-34073 ↗2026-04-03azl3 python-cryptography 42.0.5-4 on Azure Linux 3.0LowOut-of-bandcryptography has incomplete DNS name constraint enforcement on peer names
CVE-2026-32287 ↗2026-04-02cbl2 telegraf 1.29.4-22 on CBL Mariner 2.0ImportantOut-of-bandInfinite loop in github.com/antchfx/xpath
CVE-2026-29785 ↗2026-04-02cbl2 telegraf 1.29.4-22 on CBL Mariner 2.0ImportantOut-of-bandNATS Server panic via malicious compression on leafnode port
CVE-2026-33216 ↗2026-04-02cbl2 telegraf 1.29.4-22 on CBL Mariner 2.0ImportantOut-of-bandNATS has MQTT plaintext password disclosure
CVE-2026-2436 ↗2026-04-02azl3 libsoup 3.4.4-14 on Azure Linux 3.0ModerateOut-of-bandLibsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake
CVE-2026-4732 ↗2026-04-02azl3 libsndfile 1.2.2-4 on Azure Linux 3.0ImportantOut-of-bandOut-of-bounds Read Overflow in tildearrow/furnace
CVE-2026-4897 ↗2026-04-02cbl2 polkit 0.119-4 on CBL Mariner 2.0ModerateOut-of-bandPolkit: polkit: denial of service via unbounded input processing through standard input
CVE-2026-2100 ↗2026-04-02cbl2 p11-kit 0.24.1-1 on CBL Mariner 2.0ModerateOut-of-bandP11-kit: p11-kit: null dereference via c_derivekey with specific null parameters
CVE-2026-5119 ↗2026-04-02cbl2 libsoup 3.0.4-13 on CBL Mariner 2.0ModerateOut-of-bandLibsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment
CVE-2026-5121 ↗2026-04-02cbl2 libarchive 3.6.1-9 on CBL Mariner 2.0ImportantOut-of-bandLibarchive: libarchive: arbitrary code execution via integer overflow in iso9660 image processing
CVE-2026-5201 ↗2026-04-02cbl2 gdk-pixbuf2 2.40.0-8 on CBL Mariner 2.0ImportantOut-of-bandGdk-pixbuf: gdk-pixbuf: denial of service via heap-based buffer overflow when processing a specially crafted jpeg image
CVE-2026-33554 ↗2026-04-02cbl2 freeipmi 1.6.6-3 on CBL Mariner 2.0ImportantOut-of-bandipmi-oem in FreeIPMI before 1.16.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most commonly used for sensor reading (e.g., CPU temperatures through the ipmi-sensors command within FreeIPMI) and remote power control (the ipmipower command). The ipmi-oem client command implements a set of a IPMI OEM commands for specific hardware vendors. If a user has supported hardware, they may wish to use the ipmi-oem command to send a request to a server to retrieve specific information. Three subcommands were found to have exploitable buffer overflows on response messages. They are: "ipmi-oem dell get-last-post-code - get the last POST code and string describing the error on some Dell servers," "ipmi-oem supermicro extra-firmware-info - get extra firmware info on Supermic
CVE-2026-4739 ↗2026-04-02cbl2 cmake 3.21.4-23 on CBL Mariner 2.0CriticalOut-of-bandInteger overflow vulnerabilities in InsightSoftwareConsortium/ITK
CVE-2026-4046 ↗2026-04-02cbl2 glibc 2.35-10 on CBL Mariner 2.0ImportantOut-of-bandiconv crash due to assertion failure with untrusted input
CVE-2026-21711 ↗2026-04-01azl3 nodejs24 24.14.1-2 on Azure Linux 3.0ModerateOut-of-bandA flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permission` without `--allow-net` can create and expose local IPC endpoints, allowing communication with other processes on the same host outside of the intended network restriction boundary. This vulnerability affects Node.js **25.x** processes using the Permission Model where `--allow-net` is intentionally omitted to restrict network access. Note that `--allow-net` is currently an experimental feature.
CVE-2026-21713 ↗2026-04-01azl3 nodejs 20.14.0-14 on Azure Linux 3.0ModerateOut-of-bandA flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.
CVE-2026-21716 ↗2026-04-01azl3 nodejs24 24.13.0-3 on Azure Linux 3.0LowOut-of-bandAn incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their callback-based equivalents (`fs.fchmod()`, `fs.fchown()`) were correctly patched. As a result, code running under `--permission` with restricted `--allow-fs-write` can still use promise-based `FileHandle` methods to modify file permissions and ownership on already-open file descriptors, bypassing the intended write restrictions. This vulnerability affects **20.x, 22.x, 24.x, and 25.x** processes using the Permission Model where `--allow-fs-write` is intentionally restricted.
CVE-2026-21714 ↗2026-04-01azl3 nodejs24 24.13.0-3 on Azure Linux 3.0ModerateOut-of-bandA memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.
CVE-2026-21715 ↗2026-04-01azl3 nodejs 20.14.0-14 on Azure Linux 3.0LowOut-of-bandA flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still use `fs.realpathSync.native()` to check file existence, resolve symlink targets, and enumerate filesystem paths outside of permitted directories. This vulnerability affects **20.x, 22.x, 24.x, and 25.x** processes using the Permission Model where `--allow-fs-read` is intentionally restricted.
CVE-2026-34043 ↗2026-04-01cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ModerateOut-of-bandSerialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
CVE-2026-21710 ↗2026-04-01cbl2 nodejs18 18.20.3-12 on CBL Mariner 2.0ImportantOut-of-bandA flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a non-array. This exception is thrown synchronously inside a property getter and cannot be intercepted by `error` event listeners, meaning it cannot be handled without wrapping every `req.headersDistinct` access in a `try/catch`. * This vulnerability affects all Node.js HTTP servers on **20.x, 22.x, 24.x, and v25.x**
CVE-2026-21717 ↗2026-04-01azl3 nodejs 20.14.0-15 on Azure Linux 3.0ModerateOut-of-bandA flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade performance of the Node.js process. The most common trigger is any endpoint that calls `JSON.parse()` on attacker-controlled input, as JSON parsing automatically internalizes short strings into the affected hash table. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.
CVE-2026-4176 ↗2026-04-01cbl2 binutils 2.37-20 on CBL Mariner 2.0CriticalOut-of-bandPerl versions from 5.9.4 before 5.40.4-RC1, from 5.41.0 before 5.42.2-RC1, from 5.43.0 before 5.43.9 contain a vulnerable version of Compress::Raw::Zlib
CVE-2026-34714 ↗2026-04-01cbl2 vim 9.2.0240-1 on CBL Mariner 2.0ImportantOut-of-bandVim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr} injection occurs with tabpanel lacking P_MLE.
CVE-2025-66038 ↗2026-04-01cbl2 opensc 0.23.0-5 on CBL Mariner 2.0LowOut-of-bandOpenSC: `sc_compacttlv_find_tag` can return out-of-bounds pointers
CVE-2025-66037 ↗2026-04-01cbl2 opensc 0.23.0-5 on CBL Mariner 2.0LowOut-of-bandOpenSC: Out of Bounds vulnerability
CVE-2025-66215 ↗2026-04-01cbl2 opensc 0.23.0-5 on CBL Mariner 2.0LowOut-of-bandOpenSC: Stack-buffer-overflow WRITE in card-oberthur
CVE-2025-49010 ↗2026-04-01cbl2 opensc 0.23.0-5 on CBL Mariner 2.0LowOut-of-bandOpenSC: Stack-buffer-overflow WRITE in GET RESPONSE
CVE-2026-5107 ↗2026-03-31azl3 frr 10.5.0-1 on Azure Linux 3.0LowOut-of-bandFRRouting FRR EVPN Type-2 Route bgp_evpn.c process_type2_route access control
CVE-2026-33940 ↗2026-03-31cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ImportantOut-of-bandHandlebars.js has JavaScript Injection via AST Type Confusion when passing an object as dynamic partial
CVE-2026-33937 ↗2026-03-31cbl2 reaper 3.1.1-22 on CBL Mariner 2.0CriticalOut-of-bandHandlebars.js has JavaScript Injection via AST Type Confusion
CVE-2026-33939 ↗2026-03-31cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ImportantOut-of-bandHandlebars.js has Denial of Service via Malformed Decorator Syntax in Template Compilation
CVE-2026-33916 ↗2026-03-31cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ModerateOut-of-bandHandlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection
CVE-2026-33941 ↗2026-03-31cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ImportantOut-of-bandHandlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
CVE-2026-33938 ↗2026-03-31cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ImportantOut-of-bandHandlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block
CVE-2026-33542 ↗2026-03-31azl3 telegraf 1.31.0-19 on Azure Linux 3.0ModerateOut-of-bandIncus does not verify combined fingerprint when downloading images from simplestreams servers
CVE-2026-33891 ↗2026-03-31cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ImportantOut-of-bandForge has Denial of Service via Infinite Loop in BigInteger.modInverse() with Zero Input
CVE-2026-33896 ↗2026-03-31azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandForge has a basicConstraints bypass in its certificate chain verification (RFC 5280 violation)
CVE-2026-33895 ↗2026-03-31azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandForge has signature forgery in Ed25519 due to missing S > L check
CVE-2026-33750 ↗2026-03-31azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandbrace-expansion: Zero-step sequence causes process hang and memory exhaustion
CVE-2026-34353 ↗2026-03-31azl3 ocaml 5.1.1-1 on Azure Linux 3.0ModerateOut-of-bandIn OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.
CVE-2026-21712 ↗2026-03-31azl3 nodejs24 24.13.0-3 on Azure Linux 3.0ModerateOut-of-bandA flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.
CVE-2026-0964 ↗2026-03-31azl3 libssh 0.10.6-5 on Azure Linux 3.0ModerateOut-of-bandLibssh: improper sanitation of paths received from scp servers
CVE-2026-0966 ↗2026-03-31azl3 libssh 0.10.6-5 on Azure Linux 3.0ModerateOut-of-bandLibssh: buffer underflow in ssh_get_hexa() on invalid input
CVE-2026-0967 ↗2026-03-31azl3 libssh 0.10.6-5 on Azure Linux 3.0LowOut-of-bandLibssh: libssh: denial of service via inefficient regular expression processing
CVE-2026-0965 ↗2026-03-31cbl2 libssh 0.10.6-5 on CBL Mariner 2.0LowOut-of-bandLibssh: libssh: denial of service via improper configuration file handling
CVE-2026-4833 ↗2026-03-29azl3 rubygem-rdiscount 2.2.7.1-1 on Azure Linux 3.0ModerateOut-of-bandOrc discount Markdown markdown.c compile recursion
CVE-2025-70888 ↗2026-03-29cbl2 osslsigncode 2.7-1 on CBL Mariner 2.0LowOut-of-bandAn issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the osslsigncode.c component
CVE-2026-33672 ↗2026-03-29azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandPicomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
CVE-2026-33671 ↗2026-03-29azl3 nodejs24 24.13.0-3 on Azure Linux 3.0ImportantOut-of-bandPicomatch has a ReDoS vulnerability via extglob quantifiers
CVE-2025-67030 ↗2026-03-29cbl2 javapackages-bootstrap 1.5.0-7 on CBL Mariner 2.0ImportantOut-of-bandDirectory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbitrary code
CVE-2026-23399 ↗2026-03-29azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnf_tables: nft_dynset: fix possible stateful expression memleak in error path
CVE-2026-25645 ↗2026-03-29azl3 python-requests 2.31.0-3 on Azure Linux 3.0ModerateOut-of-bandRequests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
CVE-2026-33636 ↗2026-03-29cbl2 tensorflow 2.11.1-2 on CBL Mariner 2.0ImportantOut-of-bandLIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch64
CVE-2026-33416 ↗2026-03-29cbl2 qt5-qtbase 5.12.11-19 on CBL Mariner 2.0ImportantOut-of-bandLIBPNG has use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE`
CVE-2026-3591 ↗2026-03-29azl3 bind 9.20.18-1 on Azure Linux 3.0ModerateOut-of-bandA stack use-after-return flaw in SIG(0) handling code may enable ACL bypass
CVE-2026-3119 ↗2026-03-29azl3 bind 9.20.18-1 on Azure Linux 3.0ModerateOut-of-bandAuthenticated query containing a TKEY record may cause named to terminate unexpectedly
CVE-2026-3104 ↗2026-03-29azl3 bind 9.20.18-1 on Azure Linux 3.0ImportantOut-of-bandMemory leak in code preparing DNSSEC proofs of non-existence
CVE-2026-33936 ↗2026-03-29azl3 python-ecdsa 0.18.0-2 on Azure Linux 3.0ModerateOut-of-bandpython-ecdsa: Denial of Service via improper DER length validation in crafted private keys
CVE-2026-32241 ↗2026-03-29azl3 flannel 0.24.2-26 on Azure Linux 3.0ImportantOut-of-bandFlannel vulnerable to cross-node remote code execution via extension backend BackendData injection
CVE-2026-1519 ↗2026-03-29cbl2 bind 9.16.50-3 on CBL Mariner 2.0ImportantOut-of-bandExcessive NSEC3 iterations cause high CPU load during insecure delegation validation
CVE-2026-33413 ↗2026-03-28cbl2 etcd 3.5.21-4 on CBL Mariner 2.0ImportantOut-of-bandetcd: Authorization bypasses in multiple APIs
CVE-2026-33343 ↗2026-03-28cbl2 etcd 3.5.21-4 on CBL Mariner 2.0ModerateOut-of-bandetcd: Nested etcd transactions bypass RBAC authorization checks
CVE-2026-4442 ↗2026-03-27Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4442 Heap buffer overflow in CSS
CVE-2026-4680 ↗2026-03-27Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4680 Use after free in FedCM
CVE-2026-4677 ↗2026-03-27Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4677 Out of bounds read in WebAudio
CVE-2026-4679 ↗2026-03-27Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4679 Integer overflow in Fonts
CVE-2026-4675 ↗2026-03-27Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4675 Heap buffer overflow in WebGL
CVE-2026-4674 ↗2026-03-27Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4674 Out of bounds read in CSS
CVE-2026-4673 ↗2026-03-27Microsoft Edge (Chromium-based)N/AOut-of-band1%Chromium: CVE-2026-4673 Heap buffer overflow in WebAudio
CVE-2026-4678 ↗2026-03-27Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4678 Use after free in WebGPU
CVE-2026-4676 ↗2026-03-27Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-4676 Use after free in Dawn
CVE-2026-32187 ↗2026-03-27Microsoft Edge (Chromium-based)LowOut-of-bandMicrosoft Edge (Chromium-based) Defense in Depth Vulnerability - Rejected
CVE-2026-4645 ↗2026-03-27cbl2 telegraf 1.29.4-21 on CBL Mariner 2.0ImportantOut-of-bandGithub.com/antchfx/xpath: xpath: denial of service via crafted boolean xpath expressions
CVE-2026-4775 ↗2026-03-27cbl2 libtiff 4.6.0-12 on CBL Mariner 2.0ImportantOut-of-bandLibtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing
CVE-2026-4746 ↗2026-03-27cbl2 binutils 2.37-20 on CBL Mariner 2.0CriticalOut-of-bandHeap Buffer Over-Write Vulenrabilty in timeplus-io/proton
CVE-2026-4647 ↗2026-03-27cbl2 binutils 2.37-20 on CBL Mariner 2.0ModerateOut-of-bandBinutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library
CVE-2026-23396 ↗2026-03-27azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mac80211: fix NULL deref in mesh_matches_local()
CVE-2026-23397 ↗2026-03-27azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandnfnetlink_osf: validate individual option lengths in fingerprints
CVE-2026-23398 ↗2026-03-27azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandicmp: fix NULL pointer dereference in icmp_tag_validation()
CVE-2026-32647 ↗2026-03-27azl3 nginx 1.28.2-1 on Azure Linux 3.0ImportantOut-of-bandNGINX ngx_http_mp4_module vulnerability
CVE-2026-28755 ↗2026-03-27azl3 nginx 1.28.2-1 on Azure Linux 3.0ModerateOut-of-bandNGINX ngx_stream_ssl_module vulnerability
CVE-2026-28753 ↗2026-03-27azl3 nginx 1.28.2-1 on Azure Linux 3.0ModerateOut-of-bandNGINX ngx_mail_proxy_module vulnerability
CVE-2026-27784 ↗2026-03-27azl3 nginx 1.28.2-1 on Azure Linux 3.0ImportantOut-of-bandNGINX ngx_http_mp4_module vulnerability
CVE-2026-27654 ↗2026-03-27azl3 nginx 1.28.2-1 on Azure Linux 3.0ImportantOut-of-bandNGINX ngx_http_dav_module vulnerability
CVE-2026-27651 ↗2026-03-27azl3 nginx 1.28.2-1 on Azure Linux 3.0ImportantOut-of-bandNGINX ngx_mail_auth_http_module vulnerability
CVE-2026-32748 ↗2026-03-27azl3 squid 6.13-3 on Azure Linux 3.0ImportantOut-of-bandSquid has Denial of Service in ICP Response handling
CVE-2026-33515 ↗2026-03-27azl3 squid 6.13-3 on Azure Linux 3.0ModerateOut-of-bandSquid has issues in ICP message handling
CVE-2026-33526 ↗2026-03-27azl3 squid 6.13-3 on Azure Linux 3.0ImportantOut-of-bandSquid vulnerable to Denial of Service in ICP Request handling
CVE-2026-34085 ↗2026-03-27azl3 fontconfig 2.14.2-1 on Azure Linux 3.0ModerateOut-of-bandfontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
CVE-2026-23393 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandbridge: cfm: Fix race condition in peer_mep deletion
CVE-2026-23284 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: ethernet: mtk_eth_soc: Reset prog ptr to old_prog in case of error in mtk_xdp_setup()
CVE-2026-23365 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: usb: kalmia: validate USB endpoints
CVE-2026-23379 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/sched: ets: fix divide by zero in the offload path
CVE-2026-23279 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandwifi: mac80211: fix NULL pointer dereference in mesh_rx_csa_frame()
CVE-2026-23324 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandcan: usb: etas_es58x: correctly anchor the urb in the read bulk callback
CVE-2026-23367 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandwifi: radiotap: reject radiotap with unknown bits
CVE-2026-23389 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandice: Fix memory leak in ice_set_ringparam()
CVE-2026-23327 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandcxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed()
CVE-2026-23343 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandxdp: produce a warning when calculated tailroom is negative
CVE-2026-23356 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-banddrbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock()
CVE-2026-23293 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandnet: vxlan: fix nd_tbl NULL dereference when IPv6 is disabled
CVE-2026-23310 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandbpf/bonding: reject vlan+srcmac xmit_hash_policy change when XDP is loaded
CVE-2026-23347 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandcan: usb: f81604: correctly anchor the urb in the read bulk callback
CVE-2026-23317 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-banddrm/vmwgfx: Return the correct value in vmw_translate_ptr functions
CVE-2026-23289 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandIB/mthca: Add missed mthca_unmap_user_db() for mthca_create_srq()
CVE-2026-23374 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-bandblktrace: fix __this_cpu_read/write in preemptible context
CVE-2026-23395 ↗2026-03-26azl3 kernel 6.6.126.1-1 on Azure Linux 3.0CriticalOut-of-bandBluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2025-13465CVSS 8.2Red Hat Satellite 6.18registry.redhat.io/satellite/iop-remediations-rhel9@sha256:9e1aa62d0019dc33a52584e614a93edbc6111605ef0ed3cae0b9f900dbb9097e_amd64Patch ↗Advisory ↗
Red HatCVE-2025-47907CVSS 7.0Red Hat multicluster global hub 1.6.0registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:4736201438be34ef50de48b9a3d66db5afc5e5831f43c03b0997868601f6a9df_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-57810CVSS 5.3Red Hat multicluster global hub 1.6.0registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:035d205705b2efd62713bea9d05cffdc5db7a437f050c4a3e3f12746b05c29d4_arm64Patch ↗Advisory ↗
Red HatCVE-2025-58183CVSS 7.5Red Hat multicluster global hub 1.6.0registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:4736201438be34ef50de48b9a3d66db5afc5e5831f43c03b0997868601f6a9df_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-58754CVSS 5.3Red Hat multicluster global hub 1.6.0registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:035d205705b2efd62713bea9d05cffdc5db7a437f050c4a3e3f12746b05c29d4_arm64Patch ↗Advisory ↗
Red HatCVE-2025-59343CVSS 7.5Red Hat multicluster global hub 1.6.0registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:035d205705b2efd62713bea9d05cffdc5db7a437f050c4a3e3f12746b05c29d4_arm64Patch ↗Advisory ↗
Red HatCVE-2025-61726CVSS 7.5Red Hat multicluster global hub 1.6.0registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:4736201438be34ef50de48b9a3d66db5afc5e5831f43c03b0997868601f6a9df_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-61726CVSS 7.5OpenShift API for Data Protection 1.4registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:713a90e0460a0739f6a173413b7b4a4f007b9dc385a13d473eb90f42fc8488dc_amd64Patch ↗Advisory ↗
Red HatCVE-2025-61726CVSS 7.5Red Hat Ansible Automation Platform 2.6 for RHEL 9automation-gateway-proxy-0:2.6.14-1.el9.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-61726CVSS 7.5Red Hat Ansible Automation Platform 2.5 for RHEL 8automation-gateway-proxy-0:2.5.10-4.el8ap.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-61728CVSS 7.5Red Hat multicluster global hub 1.6.0registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:4736201438be34ef50de48b9a3d66db5afc5e5831f43c03b0997868601f6a9df_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-61728CVSS 7.5OpenShift API for Data Protection 1.4registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:23a27c4df14f18ee490a8d3cff7e0f15fe8dba28888ec53999dfa1c2d8df8a17_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-61729CVSS 7.5Red Hat multicluster global hub 1.6.0registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:4736201438be34ef50de48b9a3d66db5afc5e5831f43c03b0997868601f6a9df_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-66418CVSS 7.5Red Hat Satellite 6.18registry.redhat.io/satellite/iop-insights-engine-rhel9@sha256:79b070bb3101ac3fd8c9b7d0ba9425dccf9f9e76cb9430373d0c963edc0a52bb_amd64Patch ↗Advisory ↗
Red HatCVE-2025-66471CVSS 7.5Red Hat Satellite 6.18registry.redhat.io/satellite/iop-insights-engine-rhel9@sha256:79b070bb3101ac3fd8c9b7d0ba9425dccf9f9e76cb9430373d0c963edc0a52bb_amd64Patch ↗Advisory ↗
Red HatCVE-2025-68121CVSS 7.4Red Hat multicluster global hub 1.6.0registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:4736201438be34ef50de48b9a3d66db5afc5e5831f43c03b0997868601f6a9df_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-68121CVSS 7.4Red Hat Ansible Automation Platform 2.6 for RHEL 9automation-gateway-proxy-0:2.6.14-1.el9.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-68121CVSS 7.4Red Hat Ansible Automation Platform 2.5 for RHEL 8automation-gateway-proxy-0:2.5.10-4.el8ap.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-69873CVSS 7.5Red Hat Ansible Automation Platform 2.6 for RHEL 9automation-platform-ui-0:2.6.7-1.el9ap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-21441CVSS 7.5Red Hat Satellite 6.18registry.redhat.io/satellite/iop-insights-engine-rhel9@sha256:79b070bb3101ac3fd8c9b7d0ba9425dccf9f9e76cb9430373d0c963edc0a52bb_amd64Patch ↗Advisory ↗
Red HatCVE-2026-25639CVSS 7.5Red Hat Ansible Automation Platform 2.6 for RHEL 9automation-platform-ui-0:2.6.7-1.el9ap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-25990CVSS 7.3Red Hat Ansible Automation Platform 2.6 for RHEL 9python3.12-pillow-0:12.1.1-1.el9ap.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-25990CVSS 7.3Red Hat Ansible Automation Platform 2.5 for RHEL 8python3.12-pillow-0:12.1.1-1.el8ap.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-27571CVSS 7.5Red Hat multicluster global hub 1.6.0registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:035d205705b2efd62713bea9d05cffdc5db7a437f050c4a3e3f12746b05c29d4_arm64Patch ↗Advisory ↗
Red HatCVE-2026-27904CVSS 6.5Red Hat Ansible Automation Platform 2.6 for RHEL 9automation-platform-ui-0:2.6.7-1.el9ap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-29074CVSS 7.5Red Hat Ansible Automation Platform 2.6 for RHEL 9automation-platform-ui-0:2.6.7-1.el9ap.noarchPatch ↗Advisory ↗
Red HatCVE-2012-6329Moderate (Red Hat rating)Red Hat Hardened Imagesperl-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2015-8853Moderate (Red Hat rating)Red Hat Hardened Imagesperl-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2016-2381Moderate (Red Hat rating)Red Hat Hardened Imagesperl-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2017-12837CVSS 5.9Red Hat Hardened Imagesperl-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2017-12883CVSS 6.5Red Hat Hardened Imagesperl-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2018-6913CVSS 4.0Red Hat Hardened Imagesperl-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2020-10543CVSS 8.2Red Hat Hardened Imagesperl-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2022-48522CVSS 5.5Red Hat Hardened Imagesperl-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2024-56645CVSS 7.1Red Hat Enterprise Linux AppStream EUS (v.9.6)kernel-64k-debug-debuginfo-0:5.14.0-570.103.1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-13465CVSS 8.2Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/code-rhel9@sha256:1033ffe714e728e289eddaa3809e9d21915de193813339fa5c049373e3e78719_amd64Patch ↗Advisory ↗
Red HatCVE-2025-40096CVSS 7.0Red Hat Enterprise Linux AppStream EUS (v.9.6)kernel-64k-debug-debuginfo-0:5.14.0-570.103.1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-54386CVSS 6.4Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/traefik-rhel9@sha256:12ae1997a6df944284ecfb3501138c25f1a39eba23b52685b48008174a6a363a_s390xPatch ↗Advisory ↗
Red HatCVE-2025-58183CVSS 7.5Red Hat Enterprise Linux AppStream E4S (v.8.8)aardvark-dns-2:1.5.0-2.module+el8.8.0+23884+2031fc78.ppc64le::container-tools:rhel8Patch ↗Advisory ↗
Red HatCVE-2025-61140CVSS 8.8Red Hat Developer Hub 1.8registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:2e8ed97c6e6d232f66bb81dc074b8bb2712dc54004cc565fcb1d2b43a9bb2046_amd64Patch ↗Advisory ↗
Red HatCVE-2025-61726CVSS 7.5Red Hat Openshift Data Foundation 4.19registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:15da48ce459ac77baf3ba6fd5c5c231310d9f6323fea8ea68f39326031fe8d75_arm64Patch ↗Advisory ↗
Red HatCVE-2025-61726CVSS 7.5Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/code-rhel9@sha256:1033ffe714e728e289eddaa3809e9d21915de193813339fa5c049373e3e78719_amd64Patch ↗Advisory ↗
Red HatCVE-2025-61728CVSS 7.5Red Hat OpenShift Builds 1.7.3registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:19f9361c334808b39276a59adbc42c9081eaaafcbb82837f47a4e7f8571270b0_amd64Patch ↗Advisory ↗
Red HatCVE-2025-61728CVSS 7.5Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/traefik-rhel9@sha256:12ae1997a6df944284ecfb3501138c25f1a39eba23b52685b48008174a6a363a_s390xPatch ↗Advisory ↗
Red HatCVE-2025-61729CVSS 7.5Red Hat Openshift Data Foundation 4.19registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:15da48ce459ac77baf3ba6fd5c5c231310d9f6323fea8ea68f39326031fe8d75_arm64Patch ↗Advisory ↗
Red HatCVE-2025-61729CVSS 7.5Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/udi-rhel9@sha256:58111d940c17ffcef32fc2d86f19c8d0f629b89c6412fb9933ca1ad411eec48f_s390xPatch ↗Advisory ↗
Red HatCVE-2025-64756CVSS 7.5Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/udi-rhel9@sha256:58111d940c17ffcef32fc2d86f19c8d0f629b89c6412fb9933ca1ad411eec48f_s390xPatch ↗Advisory ↗
Red HatCVE-2025-65637CVSS 7.5Red Hat Enterprise Linux AppStream E4S (v.8.8)aardvark-dns-2:1.5.0-2.module+el8.8.0+23884+2031fc78.ppc64le::container-tools:rhel8Patch ↗Advisory ↗
Red HatCVE-2025-66471CVSS 7.5Red Hat OpenShift Builds 1.7.3registry.redhat.io/openshift-builds/openshift-builds-shared-resource-rhel9@sha256:19f9361c334808b39276a59adbc42c9081eaaafcbb82837f47a4e7f8571270b0_amd64Patch ↗Advisory ↗
Red HatCVE-2025-66506CVSS 7.5Red Hat OpenShift Pipelines 1.21registry.redhat.io/openshift-pipelines/pipelines-cli-tkn-rhel9@sha256:30c78cb17c2dbb124077332e5aba2626fc34833f17d9ffc43265ead4512b1215_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-66506CVSS 7.5Red Hat OpenShift Pipelines 1.21registry.redhat.io/openshift-pipelines/pipelines-operator-bundle@sha256:6585794d76cffb3f87fc7eacb905f0dd5f02476f717c911f2c0faf7c4081a080_amd64Patch ↗Advisory ↗
Red HatCVE-2025-68121CVSS 7.4Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/udi-rhel9@sha256:58111d940c17ffcef32fc2d86f19c8d0f629b89c6412fb9933ca1ad411eec48f_s390xPatch ↗Advisory ↗
Red HatCVE-2025-68800CVSS 7.3Red Hat Enterprise Linux AppStream EUS (v.9.6)kernel-64k-debug-debuginfo-0:5.14.0-570.103.1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-69873CVSS 7.5Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/code-rhel9@sha256:1033ffe714e728e289eddaa3809e9d21915de193813339fa5c049373e3e78719_amd64Patch ↗Advisory ↗
Red HatCVE-2026-1002CVSS 5.3Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/server-rhel9@sha256:4550375a1ce30dfa306ac819590e0f95f512a7f9036e756e0ed643297f7555fe_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-22045CVSS 5.9Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/traefik-rhel9@sha256:12ae1997a6df944284ecfb3501138c25f1a39eba23b52685b48008174a6a363a_s390xPatch ↗Advisory ↗
Red HatCVE-2026-23209CVSS 7.0Red Hat Enterprise Linux AppStream EUS (v.9.6)kernel-64k-debug-debuginfo-0:5.14.0-570.103.1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2359CVSS 7.5Red Hat Developer Hub 1.8registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:2e8ed97c6e6d232f66bb81dc074b8bb2712dc54004cc565fcb1d2b43a9bb2046_amd64Patch ↗Advisory ↗
Red HatCVE-2026-23745CVSS 8.2Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/udi-rhel9@sha256:58111d940c17ffcef32fc2d86f19c8d0f629b89c6412fb9933ca1ad411eec48f_s390xPatch ↗Advisory ↗
Red HatCVE-2026-23950CVSS 8.8Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/udi-rhel9@sha256:58111d940c17ffcef32fc2d86f19c8d0f629b89c6412fb9933ca1ad411eec48f_s390xPatch ↗Advisory ↗
Red HatCVE-2026-24046CVSS 9.1Red Hat Developer Hub 1.8registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:2e8ed97c6e6d232f66bb81dc074b8bb2712dc54004cc565fcb1d2b43a9bb2046_amd64Patch ↗Advisory ↗
Red HatCVE-2026-24049CVSS 7.1Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/devspaces-operator-bundle@sha256:d25e5effc8f3e6f0a02f3f1795cb83b585508b79e236b66e9a67be1511593864_amd64Patch ↗Advisory ↗
Red HatCVE-2026-24842CVSS 8.2Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/code-rhel9@sha256:1033ffe714e728e289eddaa3809e9d21915de193813339fa5c049373e3e78719_amd64Patch ↗Advisory ↗
Red HatCVE-2026-25153CVSS 7.7Red Hat Developer Hub 1.8registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:2e8ed97c6e6d232f66bb81dc074b8bb2712dc54004cc565fcb1d2b43a9bb2046_amd64Patch ↗Advisory ↗
Red HatCVE-2026-25223CVSS 7.5Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/dashboard-rhel9@sha256:272a65ee82a9484e1d4362a9f33b6cc1b0eb13d93e70b19cc3d0208f021c2bda_arm64Patch ↗Advisory ↗
Red HatCVE-2026-25639CVSS 7.5Red Hat OpenShift Pipelines 1.21registry.redhat.io/openshift-pipelines/pipelines-operator-bundle@sha256:6585794d76cffb3f87fc7eacb905f0dd5f02476f717c911f2c0faf7c4081a080_amd64Patch ↗Advisory ↗
Red HatCVE-2026-25639CVSS 7.5Red Hat Developer Hub 1.8registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:2e8ed97c6e6d232f66bb81dc074b8bb2712dc54004cc565fcb1d2b43a9bb2046_amd64Patch ↗Advisory ↗
Red HatCVE-2026-25639CVSS 7.5Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/code-rhel9@sha256:1033ffe714e728e289eddaa3809e9d21915de193813339fa5c049373e3e78719_amd64Patch ↗Advisory ↗
Red HatCVE-2026-25896CVSS 7.1Red Hat Developer Hub 1.8registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:2e8ed97c6e6d232f66bb81dc074b8bb2712dc54004cc565fcb1d2b43a9bb2046_amd64Patch ↗Advisory ↗
Red HatCVE-2026-25949CVSS 7.5Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/traefik-rhel9@sha256:12ae1997a6df944284ecfb3501138c25f1a39eba23b52685b48008174a6a363a_s390xPatch ↗Advisory ↗
Red HatCVE-2026-26278CVSS 7.5Red Hat Developer Hub 1.8registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:2e8ed97c6e6d232f66bb81dc074b8bb2712dc54004cc565fcb1d2b43a9bb2046_amd64Patch ↗Advisory ↗
Red HatCVE-2026-26960CVSS 7.1Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/code-rhel9@sha256:1033ffe714e728e289eddaa3809e9d21915de193813339fa5c049373e3e78719_amd64Patch ↗Advisory ↗
Red HatCVE-2026-26996CVSS 6.5Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/code-rhel9@sha256:1033ffe714e728e289eddaa3809e9d21915de193813339fa5c049373e3e78719_amd64Patch ↗Advisory ↗
Red HatCVE-2026-27135CVSS 7.5Red Hat Hardened Imagesnghttp2-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-27606CVSS 9.1Red Hat Developer Hub 1.8registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:2e8ed97c6e6d232f66bb81dc074b8bb2712dc54004cc565fcb1d2b43a9bb2046_amd64Patch ↗Advisory ↗
Red HatCVE-2026-27942CVSS 7.5Red Hat Developer Hub 1.8registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:2e8ed97c6e6d232f66bb81dc074b8bb2712dc54004cc565fcb1d2b43a9bb2046_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33022CVSS 6.5Red Hat OpenShift Pipelines 1.21registry.redhat.io/openshift-pipelines/pipelines-controller-rhel9@sha256:3fcac1d8ade2f968d743f6bcc1d505933746e6dd83878ff2f1656cec005a107c_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33022CVSS 6.5Red Hat OpenShift Pipelines 1.21registry.redhat.io/openshift-pipelines/pipelines-operator-bundle@sha256:6585794d76cffb3f87fc7eacb905f0dd5f02476f717c911f2c0faf7c4081a080_amd64Patch ↗Advisory ↗
Red HatCVE-2026-3304CVSS 7.5Red Hat Developer Hub 1.8registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:2e8ed97c6e6d232f66bb81dc074b8bb2712dc54004cc565fcb1d2b43a9bb2046_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Developer Hub 1.8registry.redhat.io/rhdh/rhdh-rhel9-operator@sha256:72d72d0e8b67012bfaaeae0e1fbbcf8e35c74d4d6252051eabef3e9dd979d48e_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33211CVSS 9.6Red Hat OpenShift Pipelines 1.21registry.redhat.io/openshift-pipelines/pipelines-resolvers-rhel9@sha256:0eeefa13b3b9d1a03e25ec2e3e413bcd3d6d321a6acca853d6201f8943a62894_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33211CVSS 9.6Red Hat OpenShift Pipelines 1.21registry.redhat.io/openshift-pipelines/pipelines-operator-bundle@sha256:6585794d76cffb3f87fc7eacb905f0dd5f02476f717c911f2c0faf7c4081a080_amd64Patch ↗Advisory ↗
Red HatCVE-2026-3520CVSS 7.5Red Hat Developer Hub 1.8registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:2e8ed97c6e6d232f66bb81dc074b8bb2712dc54004cc565fcb1d2b43a9bb2046_amd64Patch ↗Advisory ↗
Red HatCVE-2026-4519CVSS 7.1Red Hat Hardened Imagespython3-12-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2025-15366CVSS 7.1Red Hat Hardened Imagespython3-13-main@aarch64Patch ↗Advisory ↗