CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Vulnerabilities

March 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 0 vulnerabilities with exploitation detected in the wild this month. This defender-focused view covers 1,069 vulnerabilities across 3,314 returned patch records from 4 vendors. Filter the complete month, or browse the static page trail without JavaScript.

3,314all patch recordsClear filters78criticalShow these records0Microsoft exploitation detectedShow these records2Microsoft in the Known Exploited Vulnerabilities catalogShow these records1,099tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

My Stack only keeps records whose vendor you have pinned. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 14 of 17 · records 2,601 to 2,800 of 3,314

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-23385 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nf_tables: clone set on flush only
CVE-2026-4948 ↗cbl2 firewalld 1.0.3-2 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableFirewalld: firewalld: local unprivileged user can modify firewall state due to d-bus setter mis-authorization
CVE-2026-23362 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecan: bcm: fix locking for bcm_op runtime updates
CVE-2026-23394 ↗azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableaf_unix: Give up GC if MSG_PEEK intervened.
CVE-2026-23360 ↗azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenvme: fix admin queue leak on controller reset
CVE-2026-2436 ↗azl3 libsoup 3.4.4-14 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLibsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake
CVE-2026-4897 ↗cbl2 polkit 0.119-4 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePolkit: polkit: denial of service via unbounded input processing through standard input
CVE-2026-2100 ↗cbl2 p11-kit 0.24.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableP11-kit: p11-kit: null dereference via c_derivekey with specific null parameters
CVE-2026-5119 ↗cbl2 libsoup 3.0.4-13 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLibsoup: libsoup: information disclosure via cleartext transmission of cookies during https tunnel establishment
CVE-2026-21711 ↗azl3 nodejs24 24.14.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableA flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permission` without `--allow-net` can create and expose local IPC endpoints, allowing communication with other processes on the same host outside of the intended network restriction boundary. This vulnerability affects Node.js **25.x** processes using the Permission Model where `--allow-net` is intentionally omitted to restrict network access. Note that `--allow-net` is currently an experimental feature.
CVE-2026-21713 ↗azl3 nodejs 20.14.0-14 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableA flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.
CVE-2026-21714 ↗azl3 nodejs24 24.13.0-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableA memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.
CVE-2026-34043 ↗cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableSerialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like objects
CVE-2026-21717 ↗cbl2 nodejs18 18.20.3-12 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableA flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade performance of the Node.js process. The most common trigger is any endpoint that calls `JSON.parse()` on attacker-controlled input, as JSON parsing automatically internalizes short strings into the affected hash table. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.
CVE-2026-33916 ↗cbl2 reaper 3.1.1-22 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableHandlebars.js has Prototype Pollution Leading to XSS through Partial Template Injection
CVE-2026-33542 ↗azl3 telegraf 1.31.0-15 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableIncus does not verify combined fingerprint when downloading images from simplestreams servers
CVE-2026-33750 ↗cbl2 nodejs18 18.20.3-11 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebrace-expansion: Zero-step sequence causes process hang and memory exhaustion
CVE-2026-34353 ↗azl3 ocaml 5.1.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableIn OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.
CVE-2026-21712 ↗azl3 nodejs24 24.13.0-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableA flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.
CVE-2026-0964 ↗azl3 libssh 0.10.6-5 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLibssh: improper sanitation of paths received from scp servers
CVE-2026-0966 ↗azl3 libssh 0.10.6-5 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLibssh: buffer underflow in ssh_get_hexa() on invalid input
CVE-2026-4833 ↗azl3 rubygem-rdiscount 2.2.7.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableOrc discount Markdown markdown.c compile recursion
CVE-2026-33672 ↗azl3 nodejs24 24.13.0-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePicomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching
CVE-2026-23399 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenf_tables: nft_dynset: fix possible stateful expression memleak in error path
CVE-2026-25645 ↗cbl2 python-requests 2.27.1-8 on CBL-Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRequests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
CVE-2026-3591 ↗azl3 bind 9.20.18-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableA stack use-after-return flaw in SIG(0) handling code may enable ACL bypass
CVE-2026-3119 ↗azl3 bind 9.20.18-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableAuthenticated query containing a TKEY record may cause named to terminate unexpectedly
CVE-2026-33936 ↗cbl2 python-ecdsa 0.17.0-1 on CBL-Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepython-ecdsa: Denial of Service via improper DER length validation in crafted private keys
CVE-2026-33343 ↗cbl2 etcd 3.5.21-4 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableetcd: Nested etcd transactions bypass RBAC authorization checks
CVE-2026-4647 ↗cbl2 binutils 2.37-20 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBinutils: out-of-bounds read in xcoff relocation processing in gnu binutils bfd library
CVE-2026-23396 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mac80211: fix NULL deref in mesh_matches_local()
CVE-2026-23398 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableicmp: fix NULL pointer dereference in icmp_tag_validation()
CVE-2026-28755 ↗azl3 nginx 1.28.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableNGINX ngx_stream_ssl_module vulnerability
CVE-2026-28753 ↗azl3 nginx 1.28.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableNGINX ngx_mail_proxy_module vulnerability
CVE-2026-33515 ↗azl3 squid 6.13-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableSquid has issues in ICP message handling
CVE-2026-34085 ↗azl3 fontconfig 2.14.2-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte out-of-bounds write, and potentially a crash or code execution. This is in FcFontCapabilities in fcfreetype.c.
CVE-2026-23284 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: ethernet: mtk_eth_soc: Reset prog ptr to old_prog in case of error in mtk_xdp_setup()
CVE-2026-23365 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: usb: kalmia: validate USB endpoints
CVE-2026-23379 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/sched: ets: fix divide by zero in the offload path
CVE-2026-23279 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mac80211: fix NULL pointer dereference in mesh_rx_csa_frame()
CVE-2026-23324 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecan: usb: etas_es58x: correctly anchor the urb in the read bulk callback
CVE-2026-23389 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableice: Fix memory leak in ice_set_ringparam()
CVE-2026-23356 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrbd: fix "LOGIC BUG" in drbd_al_begin_io_nonblock()
CVE-2026-23347 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecan: usb: f81604: correctly anchor the urb in the read bulk callback
CVE-2026-23317 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/vmwgfx: Return the correct value in vmw_translate_ptr functions
CVE-2026-23381 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: bridge: fix nd_tbl NULL dereference when IPv6 is disabled
CVE-2026-23319 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Fix a UAF issue in bpf_trampoline_link_cgroup_shim
CVE-2026-23357 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecan: mcp251x: fix deadlock in error path of mcp251x_open
CVE-2026-23291 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenfc: pn533: properly drop the usb interface reference on disconnect
CVE-2026-23302 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: annotate data-races around sk->sk_{data_ready,write_space}
CVE-2026-23371 ↗azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesched/deadline: Fix missing ENQUEUE_REPLENISH during PI de-boosting
CVE-2026-23335 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/irdma: Fix kernel stack leak in irdma_create_user_ah()
CVE-2026-23298 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecan: ucan: Fix infinite loop from zero-length messages
CVE-2026-23339 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenfc: nci: free skb on nci_transceive early error paths
CVE-2026-23290 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: usb: pegasus: validate USB endpoints
CVE-2026-23320 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableusb: gadget: f_ncm: align net_device lifecycle with bind/unbind
CVE-2026-23304 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableipv6: fix NULL pointer deref in ip6_rt_get_dev_rcu()
CVE-2026-23303 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesmb: client: Don't log plaintext credentials in cifs_set_cifscreds
CVE-2026-23334 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecan: usb: f81604: handle short interrupt urb messages properly
CVE-2026-23348 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecxl: Fix race of nvdimm_bus object when creating nvdimm objects
CVE-2026-23346 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablearm64: io: Extract user memory type in ioremap_prot()
CVE-2026-23307 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecan: ems_usb: ems_usb_read_bulk_callback(): check the proper length of a message
CVE-2026-23383 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf, arm64: Force 8-byte alignment for JIT buffer to prevent atomic tearing
CVE-2026-23292 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: target: Fix recursive locking in __configfs_open_file()
CVE-2026-23390 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletracing/dma: Cap dma_map_sg tracepoint arrays to prevent buffer overflow
CVE-2026-23368 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: phy: register phy led_triggers during probe to avoid AB-BA deadlock
CVE-2026-23286 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableatm: lec: fix null-ptr-deref in lec_arp_clear_vccs
CVE-2026-23285 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrbd: fix null-pointer dereference on local read error
CVE-2026-23330 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenfc: nci: complete pending data exchange on device close
CVE-2026-23312 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: usb: kaweth: validate USB endpoints
CVE-2026-23382 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableHID: Add HID_CLAIMED_INPUT guards in raw_event callbacks missing them
CVE-2026-23333 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nft_set_rbtree: validate open interval overlap
CVE-2026-23370 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableplatform/x86: dell-wmi-sysman: Don't hex dump plaintext password data
CVE-2026-29111 ↗cbl2 systemd-bootstrap 250.3-13 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesystemd: Local unprivileged user can trigger an assert
CVE-2026-33412 ↗azl3 vim 9.2.0088-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVim affected by Command injection via newline in glob()
CVE-2026-2646 ↗cbl2 mariadb 10.6.24-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableHeap buffer overflow in session parsing with wolfSSL_d2i_SSL_SESSION() function
CVE-2026-2645 ↗cbl2 mariadb 10.6.24-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableAcceptance of CertificateVerify Message before ClientKeyExchange in TLS 1.2
CVE-2026-3503 ↗cbl2 mariadb 10.6.24-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableFault injection attack with ML-DSA and ML-KEM on ARM
CVE-2026-3849 ↗cbl2 mariadb 10.6.24-1 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBuffer Overflow in HPKE via Oversized ECH Config
CVE-2026-2369 ↗cbl2 libsoup 3.0.4-12 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLibsoup: libsoup: buffer overread due to integer underflow when handling zero-length resources
CVE-2026-3099 ↗azl3 libsoup 3.4.4-12 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLibsoup: libsoup: authentication bypass via digest authentication replay attack

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-2782trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.8.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2782trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.8.0-2.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2784trackedCVSS 6.1Red Hat Enterprise Linux AppStream AUS (v.8.4)firefox-0:140.8.0-2.el8_4.srcPatch ↗Advisory ↗
Red HatCVE-2026-2784trackedCVSS 6.1Red Hat Enterprise Linux AppStream AUS (v. 8.2)firefox-0:140.8.0-2.el8_2.srcPatch ↗Advisory ↗
Red HatCVE-2026-2784trackedCVSS 6.1Red Hat Enterprise Linux AppStream E4S (v.9.0)firefox-0:140.8.0-2.el9_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2784trackedCVSS 6.1Red Hat Enterprise Linux AppStream E4S (v.8.8)firefox-0:140.8.0-2.el8_8.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-2784trackedCVSS 6.1Red Hat Enterprise Linux AppStream AUS (v.8.6)firefox-0:140.8.0-2.el8_6.srcPatch ↗Advisory ↗
Red HatCVE-2026-2784trackedCVSS 6.1Red Hat Enterprise Linux AppStream EUS (v.9.4)firefox-0:140.8.0-2.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2784trackedCVSS 6.1Red Hat Enterprise Linux AppStream EUS (v.9.6)firefox-0:140.8.0-2.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2784trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 8)thunderbird-0:140.8.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2784trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.8.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2784trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.8.0-2.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2785trackedCVSS 6.1Red Hat Enterprise Linux AppStream AUS (v.8.4)firefox-0:140.8.0-2.el8_4.srcPatch ↗Advisory ↗
Red HatCVE-2026-2785trackedCVSS 6.1Red Hat Enterprise Linux AppStream AUS (v. 8.2)firefox-0:140.8.0-2.el8_2.srcPatch ↗Advisory ↗
Red HatCVE-2026-2785trackedCVSS 6.1Red Hat Enterprise Linux AppStream E4S (v.9.0)firefox-0:140.8.0-2.el9_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2785trackedCVSS 6.1Red Hat Enterprise Linux AppStream E4S (v.8.8)firefox-0:140.8.0-2.el8_8.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-2785trackedCVSS 6.1Red Hat Enterprise Linux AppStream AUS (v.8.6)firefox-0:140.8.0-2.el8_6.srcPatch ↗Advisory ↗
Red HatCVE-2026-2785trackedCVSS 6.1Red Hat Enterprise Linux AppStream EUS (v.9.4)firefox-0:140.8.0-2.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2785trackedCVSS 6.1Red Hat Enterprise Linux AppStream EUS (v.9.6)firefox-0:140.8.0-2.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2785trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 8)thunderbird-0:140.8.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2785trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.8.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2785trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.8.0-2.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2786trackedCVSS 6.1Red Hat Enterprise Linux AppStream AUS (v.8.4)firefox-0:140.8.0-2.el8_4.srcPatch ↗Advisory ↗
Red HatCVE-2026-2786trackedCVSS 6.1Red Hat Enterprise Linux AppStream AUS (v. 8.2)firefox-0:140.8.0-2.el8_2.srcPatch ↗Advisory ↗
Red HatCVE-2026-2786trackedCVSS 6.1Red Hat Enterprise Linux AppStream E4S (v.9.0)firefox-0:140.8.0-2.el9_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2786trackedCVSS 6.1Red Hat Enterprise Linux AppStream E4S (v.8.8)firefox-0:140.8.0-2.el8_8.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-2786trackedCVSS 6.1Red Hat Enterprise Linux AppStream AUS (v.8.6)firefox-0:140.8.0-2.el8_6.srcPatch ↗Advisory ↗
Red HatCVE-2026-2786trackedCVSS 6.1Red Hat Enterprise Linux AppStream EUS (v.9.4)firefox-0:140.8.0-2.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2786trackedCVSS 6.1Red Hat Enterprise Linux AppStream EUS (v.9.6)firefox-0:140.8.0-2.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2786trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 8)thunderbird-0:140.8.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2786trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.8.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2786trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.8.0-2.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2787trackedCVSS 6.1Red Hat Enterprise Linux AppStream AUS (v.8.4)firefox-0:140.8.0-2.el8_4.srcPatch ↗Advisory ↗
Red HatCVE-2026-2787trackedCVSS 6.1Red Hat Enterprise Linux AppStream AUS (v. 8.2)firefox-0:140.8.0-2.el8_2.srcPatch ↗Advisory ↗
Red HatCVE-2026-2787trackedCVSS 6.1Red Hat Enterprise Linux AppStream E4S (v.9.0)firefox-0:140.8.0-2.el9_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2787trackedCVSS 6.1Red Hat Enterprise Linux AppStream E4S (v.8.8)firefox-0:140.8.0-2.el8_8.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-2787trackedCVSS 6.1Red Hat Enterprise Linux AppStream AUS (v.8.6)firefox-0:140.8.0-2.el8_6.srcPatch ↗Advisory ↗
Red HatCVE-2026-2787trackedCVSS 6.1Red Hat Enterprise Linux AppStream EUS (v.9.4)firefox-0:140.8.0-2.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2787trackedCVSS 6.1Red Hat Enterprise Linux AppStream EUS (v.9.6)firefox-0:140.8.0-2.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2787trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 8)thunderbird-0:140.8.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2787trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.8.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2787trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.8.0-2.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2788trackedCVSS 6.1Red Hat Enterprise Linux AppStream AUS (v.8.4)firefox-0:140.8.0-2.el8_4.srcPatch ↗Advisory ↗
Red HatCVE-2026-2788trackedCVSS 6.1Red Hat Enterprise Linux AppStream AUS (v. 8.2)firefox-0:140.8.0-2.el8_2.srcPatch ↗Advisory ↗
Red HatCVE-2026-2788trackedCVSS 6.1Red Hat Enterprise Linux AppStream E4S (v.9.0)firefox-0:140.8.0-2.el9_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2788trackedCVSS 6.1Red Hat Enterprise Linux AppStream E4S (v.8.8)firefox-0:140.8.0-2.el8_8.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-2788trackedCVSS 6.1Red Hat Enterprise Linux AppStream AUS (v.8.6)firefox-0:140.8.0-2.el8_6.srcPatch ↗Advisory ↗
Red HatCVE-2026-2788trackedCVSS 6.1Red Hat Enterprise Linux AppStream EUS (v.9.4)firefox-0:140.8.0-2.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2788trackedCVSS 6.1Red Hat Enterprise Linux AppStream EUS (v.9.6)firefox-0:140.8.0-2.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2788trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 8)thunderbird-0:140.8.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2788trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.8.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2788trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.8.0-2.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2789trackedCVSS 6.1Red Hat Enterprise Linux AppStream AUS (v.8.4)firefox-0:140.8.0-2.el8_4.srcPatch ↗Advisory ↗
Red HatCVE-2026-2789trackedCVSS 6.1Red Hat Enterprise Linux AppStream AUS (v. 8.2)firefox-0:140.8.0-2.el8_2.srcPatch ↗Advisory ↗
Red HatCVE-2026-2789trackedCVSS 6.1Red Hat Enterprise Linux AppStream E4S (v.9.0)firefox-0:140.8.0-2.el9_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2789trackedCVSS 6.1Red Hat Enterprise Linux AppStream E4S (v.8.8)firefox-0:140.8.0-2.el8_8.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-2789trackedCVSS 6.1Red Hat Enterprise Linux AppStream AUS (v.8.6)firefox-0:140.8.0-2.el8_6.srcPatch ↗Advisory ↗
Red HatCVE-2026-2789trackedCVSS 6.1Red Hat Enterprise Linux AppStream EUS (v.9.4)firefox-0:140.8.0-2.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2789trackedCVSS 6.1Red Hat Enterprise Linux AppStream EUS (v.9.6)firefox-0:140.8.0-2.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2789trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 8)thunderbird-0:140.8.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2789trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.8.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2789trackedCVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.8.0-2.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2023-40403CVSS 6.5Red Hat Enterprise Linux AppStream (v. 9)libxslt-0:1.1.34-14.el9_7.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-57810CVSS 5.3Red Hat multicluster global hub 1.6.0registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:035d205705b2efd62713bea9d05cffdc5db7a437f050c4a3e3f12746b05c29d4_arm64Patch ↗Advisory ↗
Red HatCVE-2025-58754CVSS 5.3Red Hat multicluster global hub 1.6.0registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:035d205705b2efd62713bea9d05cffdc5db7a437f050c4a3e3f12746b05c29d4_arm64Patch ↗Advisory ↗
Red HatCVE-2026-0865CVSS 4.5Red Hat Enterprise Linux AppStream EUS (v.9.4)python3.11-0:3.11.7-1.el9_4.11.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-1642CVSS 5.9Red Hat Enterprise Linux AppStream EUS (v.9.4)nginx-1:1.20.1-16.el9_4.4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-1642CVSS 5.9Red Hat Enterprise Linux AppStream E4S (v.9.2)nginx-1:1.20.1-14.el9_2.4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-1642CVSS 5.9Red Hat Enterprise Linux AppStream EUS (v.9.6)nginx-1:1.24.0-4.module+el9.6.0+24139+44cdd49a.1.aarch64::nginx:1.24Patch ↗Advisory ↗
Red HatCVE-2026-27904CVSS 6.5Red Hat Ansible Automation Platform 2.6 for RHEL 9automation-platform-ui-0:2.6.7-1.el9ap.noarchPatch ↗Advisory ↗
Red HatCVE-2012-6329Moderate (Red Hat rating)Red Hat Hardened Imagesperl-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2015-8853Moderate (Red Hat rating)Red Hat Hardened Imagesperl-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2016-2381Moderate (Red Hat rating)Red Hat Hardened Imagesperl-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2017-12837CVSS 5.9Red Hat Hardened Imagesperl-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2017-12883CVSS 6.5Red Hat Hardened Imagesperl-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2018-6913CVSS 4.0Red Hat Hardened Imagesperl-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2022-48522CVSS 5.5Red Hat Hardened Imagesperl-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2025-4949CVSS 4.8Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7 Servereap7-eclipse-jgit-0:5.13.5.202508271544-1.r_redhat_00001.1.el7eap.noarchPatch ↗Advisory ↗
Red HatCVE-2025-54386CVSS 6.4Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/traefik-rhel9@sha256:12ae1997a6df944284ecfb3501138c25f1a39eba23b52685b48008174a6a363a_s390xPatch ↗Advisory ↗
Red HatCVE-2026-1002CVSS 5.3Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/server-rhel9@sha256:4550375a1ce30dfa306ac819590e0f95f512a7f9036e756e0ed643297f7555fe_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-1642CVSS 5.9Red Hat Enterprise Linux AppStream EUS (v.9.6)nginx-2:1.20.1-22.el9_6.4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-22045CVSS 5.9Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/traefik-rhel9@sha256:12ae1997a6df944284ecfb3501138c25f1a39eba23b52685b48008174a6a363a_s390xPatch ↗Advisory ↗
Red HatCVE-2026-23893CVSS 6.8Red Hat Enterprise Linux BaseOS EUS (v.9.4)opencryptoki-0:3.22.0-3.el9_4.2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-26996CVSS 6.5Red Hat OpenShift Dev Spaces 3.27registry.redhat.io/devspaces/code-rhel9@sha256:1033ffe714e728e289eddaa3809e9d21915de193813339fa5c049373e3e78719_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33022CVSS 6.5Red Hat OpenShift Pipelines 1.21registry.redhat.io/openshift-pipelines/pipelines-controller-rhel9@sha256:3fcac1d8ade2f968d743f6bcc1d505933746e6dd83878ff2f1656cec005a107c_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33022CVSS 6.5Red Hat OpenShift Pipelines 1.21registry.redhat.io/openshift-pipelines/pipelines-operator-bundle@sha256:6585794d76cffb3f87fc7eacb905f0dd5f02476f717c911f2c0faf7c4081a080_amd64Patch ↗Advisory ↗
Red HatCVE-2026-3889CVSS 5.4Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.9.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4706CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.9.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4707CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.9.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4708CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.9.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4709CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.9.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4712CVSS 6.5Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.9.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4713CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.9.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4714CVSS 6.5Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.9.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-23893CVSS 6.8Red Hat Enterprise Linux BaseOS EUS (v. 10.0)opencryptoki-0:3.24.0-6.el10_0.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-23893CVSS 6.8Red Hat Enterprise Linux BaseOS EUS (v.9.6)opencryptoki-0:3.24.0-5.el9_6.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4324CVSS 5.4Red Hat Satellite 6.18 for RHEL 9rubygem-katello-0:4.18.0.9-1.el9sat.noarchPatch ↗Advisory ↗
Red HatCVE-2026-4324CVSS 5.4Red Hat Satellite 6.17 for RHEL 9foreman-0:3.14.0.14-1.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-4706CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.9.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4706CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)firefox-0:140.9.0-1.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4706CVSS 6.1Red Hat Enterprise Linux AppStream (v. 8)firefox-0:140.9.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4707CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.9.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4707CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)firefox-0:140.9.0-1.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4707CVSS 6.1Red Hat Enterprise Linux AppStream (v. 8)firefox-0:140.9.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4708CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.9.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4708CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)firefox-0:140.9.0-1.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4708CVSS 6.1Red Hat Enterprise Linux AppStream (v. 8)firefox-0:140.9.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4709CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.9.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4709CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)firefox-0:140.9.0-1.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4709CVSS 6.1Red Hat Enterprise Linux AppStream (v. 8)firefox-0:140.9.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4712CVSS 6.5Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.9.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4712CVSS 6.5Red Hat Enterprise Linux AppStream (v. 10)firefox-0:140.9.0-1.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4712CVSS 6.5Red Hat Enterprise Linux AppStream (v. 8)firefox-0:140.9.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4713CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.9.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4713CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)firefox-0:140.9.0-1.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4713CVSS 6.1Red Hat Enterprise Linux AppStream (v. 8)firefox-0:140.9.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4714CVSS 6.5Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.9.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4714CVSS 6.5Red Hat Enterprise Linux AppStream (v. 10)firefox-0:140.9.0-1.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4714CVSS 6.5Red Hat Enterprise Linux AppStream (v. 8)firefox-0:140.9.0-1.el8_10.aarch64Patch ↗Advisory ↗

Glossary