CYBERSECURITYTRACKER
TRACKING3,612 stories653 vuln stories
Patch Day month

April 2026 vulnerabilities

A server-rendered hunting trail for April 2026: 1,904 returned patch records across 4 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.

1,904all patches
140critical
2exploitation detected
5in CISA KEV
322tracked here
Red Hat 1,131Microsoft 737Cisco 31Android 5

Page 2 of 10 · records 201–400 of 1,904

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-3298 ↗2026-04-27azl3 python3 3.12.9-10 on Azure Linux 3.0ImportantOut-of-bandOut-of-bounds write in Windows asyncio.ProacterEventLoop.sock_recvfrom_into() when using nbytes
CVE-2026-41305 ↗2026-04-27azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandPostCSS has XSS via Unescaped </style> in its CSS Stringify Output
CVE-2026-31656 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-banddrm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat
CVE-2026-31658 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnet: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit()
CVE-2026-31592 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandKVM: SEV: Protect *all* of sev_mem_enc_register_region() with kvm->lock
CVE-2026-31597 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY
CVE-2026-31622 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandNFC: digital: Bounds check NFC-A cascade depth in SDD response handler
CVE-2026-31664 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandxfrm: clear trailing padding in build_polexpire()
CVE-2026-31673 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandaf_unix: read UNIX_DIAG_VFS data under unix_state_lock
CVE-2026-31659 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0CriticalOut-of-bandbatman-adv: reject oversized global TT response buffers
CVE-2026-31679 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandopenvswitch: validate MPLS set/set_masked payload length
CVE-2026-31625 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandHID: alps: fix NULL pointer dereference in alps_raw_event()
CVE-2026-31674 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandnetfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check()
CVE-2026-31634 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandrxrpc: fix reference count leak in rxrpc_server_keyring()
CVE-2026-31682 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandbridge: br_nd_send: linearize skb before parsing ND options
CVE-2026-31578 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandmedia: as102: fix to not free memory after the device is registered in as102_usb_probe()
CVE-2026-31684 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnet: sched: act_csum: validate nested VLAN headers
CVE-2026-31586 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandmm: blk-cgroup: fix use-after-free in cgwb_release_workfn()
CVE-2026-31681 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnetfilter: xt_multiport: validate range encoding in checkentry
CVE-2026-31595 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandPCI: endpoint: pci-epf-vntb: Stop cmd_handler work in epf_ntb_epc_cleanup
CVE-2026-31678 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandopenvswitch: defer tunnel netdev_put to RCU release
CVE-2026-31576 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandmedia: hackrf: fix to not free memory after the device is registered in hackrf_probe()
CVE-2026-31680 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnet: ipv6: flowlabel: defer exclusive option free until RCU teardown
CVE-2026-31588 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandKVM: x86: Use scratch field in MMIO fragment to hold small write values
CVE-2026-31677 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandcrypto: af_alg - limit RX SG extraction by receive buffer budget
CVE-2026-31649 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: stmmac: fix integer underflow in chain mode
CVE-2026-31676 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandrxrpc: only handle RESPONSE during service challenge
CVE-2026-31582 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandhwmon: (powerz) Fix use-after-free on USB disconnect
CVE-2026-31675 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandnet/sched: sch_netem: fix out-of-bounds access in packet corruption
CVE-2026-31669 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0CriticalOut-of-bandmptcp: fix slab-use-after-free in __inet_lookup_established
CVE-2026-31685 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandnetfilter: ip6t_eui64: reject invalid MAC header for all packets
CVE-2026-31655 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandpmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled
CVE-2026-31628 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandx86/CPU: Fix FPDSS on Zen1
CVE-2026-31579 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandwireguard: device: use exit_rtnl callback instead of manual rtnl_lock in pre_exit
CVE-2026-31630 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandrxrpc: proc: size address buffers for %pISpc output
CVE-2026-31629 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandnfc: llcp: add missing return after LLCP_CLOSED checks
CVE-2026-31591 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandKVM: SEV: Lock all vCPUs when synchronzing VMSAs for SNP launch finish
CVE-2026-31639 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandrxrpc: Fix key reference count leak from call->key
CVE-2026-31668 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0CriticalOut-of-bandseg6: separate dst_cache for input and output paths in seg6 lwtunnel
CVE-2026-41681 ↗2026-04-26azl3 python-cryptography 42.0.5-4 on Azure Linux 3.0ImportantOut-of-bandrust-openssl: MdCtxRef::digest_final() writes past caller buffer with no length check
CVE-2026-31657 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0CriticalOut-of-bandbatman-adv: hold claim backbone gateways by reference
CVE-2026-31616 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandusb: gadget: f_phonet: fix skb frags[] overflow in pn_rx_complete()
CVE-2026-31601 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandvfio/xe: Reorganize the init to decouple migration from reset
CVE-2026-31580 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandbcache: fix cached_dev.sb_bio use-after-free and crash
CVE-2026-41677 ↗2026-04-26cbl2 rust 1.72.0-15 on CBL Mariner 2.0LowOut-of-bandrust-openssl: Out-of-bounds read in PEM password callback when user callback returns an oversized length
CVE-2026-31662 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandtipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG
CVE-2026-31587 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandASoC: qcom: q6apm: move component registration to unmanaged version
CVE-2026-31575 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandmm/userfaultfd: fix hugetlb fault mutex hash calculation
CVE-2026-31609 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandsmb: client: avoid double-free in smbd_free_send_io() after smbd_send_batch_flush()
CVE-2026-31568 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bands390/mm: Add missing secure storage access fixups for donated memory
CVE-2026-41678 ↗2026-04-26azl3 clamav 1.5.2-1 on Azure Linux 3.0ImportantOut-of-bandrust-openssl: Incorrect bounds assertion in aes key wrap
CVE-2026-31612 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandksmbd: validate EaNameLength in smb2_get_ea()
CVE-2026-31623 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnet: usb: cdc-phonet: fix skb frags[] overflow in rx_complete()
CVE-2026-31594 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandPCI: endpoint: pci-epf-vntb: Remove duplicate resource teardown
CVE-2026-31613 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandsmb: client: fix OOB reads parsing symlink error response
CVE-2026-41676 ↗2026-04-26cbl2 rpm-ostree 2022.1-8 on CBL Mariner 2.0ImportantOut-of-bandrust-openssl: Deriver::derive and PkeyCtxRef::derive can overflow short buffers on OpenSSL 1.1.1
CVE-2026-31560 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandspi: spi-dw-dma: fix print error log when wait finish transaction
CVE-2026-31671 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandxfrm_user: fix info leak in build_report()
CVE-2026-31627 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandi2c: s3c24xx: check the size of the SMBUS message before using it
CVE-2026-31600 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandarm64: mm: Handle invalid large leaf mappings correctly
CVE-2026-32147 ↗2026-04-26azl3 erlang 26.2.5.18-1 on Azure Linux 3.0ModerateOut-of-bandSFTP chroot bypass via path traversal in SSH_FXP_FSETSTAT
CVE-2026-31642 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandrxrpc: Fix call removal to use RCU safe deletion
CVE-2026-31611 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandksmbd: require 3 sub-authorities before reading sub_auth[2]
CVE-2026-31608 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandsmb: server: avoid double-free in smb_direct_free_sendmsg after smb_direct_flush_send_list()
CVE-2026-23414 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandtls: Purge async_hold in tls_decrypt_async_wait()
CVE-2026-31603 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandstaging: sm750fb: fix division by zero in ps_to_hz()
CVE-2026-31537 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandsmb: server: make use of smbdirect_socket.send_io.bcredits
CVE-2026-31670 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnet: rfkill: prevent unlimited numbers of rfkill events from being created
CVE-2026-31598 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandocfs2: fix possible deadlock between unlink and dio_end_io_write
CVE-2026-41411 ↗2026-04-26azl3 vim 9.2.0240-1 on Azure Linux 3.0ModerateOut-of-bandVim: Command injection via backtick expansion in tag filenames
CVE-2026-31645 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: lan966x: fix page pool leak in error paths
CVE-2026-41907 ↗2026-04-26azl3 uuid 1.6.2-51 on Azure Linux 3.0ImportantOut-of-banduuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is provided
CVE-2026-31610 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandksmbd: fix mechToken leak when SPNEGO decode fails after token alloc
CVE-2026-31615 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: renesas_usb3: validate endpoint index in standard request handlers
CVE-2026-41066 ↗2026-04-26azl3 python-lxml 4.9.3-1 on Azure Linux 3.0ImportantOut-of-bandlxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
CVE-2026-31665 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nft_ct: fix use-after-free in timeout object destroy
CVE-2026-41140 ↗2026-04-26azl3 poetry 1.8.3-1 on Azure Linux 3.0LowOut-of-bandPoetry: Path traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4
CVE-2026-31577 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandnilfs2: fix NULL i_assoc_inode dereference in nilfs_mdt_save_to_shadow_map
CVE-2026-31585 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandmedia: vidtv: fix nfeeds state corruption on start_streaming failure
CVE-2026-31663 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandxfrm: hold dev ref until after transport_finish NF_HOOK
CVE-2026-31604 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandwifi: rtw88: fix device leak on probe failure
CVE-2026-31626 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandstaging: rtl8723bs: initialize le_tmp64 in rtw_BIP_verify()
CVE-2026-31581 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandALSA: 6fire: fix use-after-free on disconnect
CVE-2026-31621 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandbnge: return after auxiliary_device_uninit() in error path
CVE-2026-31565 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandRDMA/irdma: Fix deadlock during netdev reset with active connections
CVE-2026-23422 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-banddpaa2-switch: Fix interrupt storm after receiving bad if_id in IRQ handler
CVE-2026-31672 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandwifi: rt2x00usb: fix devres lifetime
CVE-2026-23420 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandwifi: wlcore: Fix a locking bug
CVE-2026-31651 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandmmc: vub300: fix NULL-deref on disconnect
CVE-2026-31624 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandHID: core: clamp report_size in s32ton() to avoid undefined shift
CVE-2026-31570 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandcan: gw: fix OOB heap access in cgw_csum_crc8_rel()
CVE-2026-31637 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandrxrpc: reject undecryptable rxkad response tickets
CVE-2026-31602 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandALSA: ctxfi: Limit PTP to a single page
CVE-2026-31599 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandmedia: vidtv: fix NULL pointer dereference in vidtv_channel_pmt_match_sections
CVE-2026-31566 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib
CVE-2026-31605 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandfbdev: udlfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO
CVE-2026-31596 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandocfs2: handle invalid dinode in ocfs2_group_extend
CVE-2026-31660 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnfc: pn533: allocate rx skb before consuming bytes
CVE-2026-31574 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandclockevents: Add missing resets of the next_event_forced flag
CVE-2026-31589 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandmm: call ->free_folio() directly in folio_unmap_invalidate()
CVE-2026-31638 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandrxrpc: Only put the call ref if one was acquired
CVE-2026-31617 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandusb: gadget: f_ncm: validate minimum block_len in ncm_unwrap_ntb()
CVE-2026-31583 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandmedia: em28xx: fix use-after-free in em28xx_v4l2_open()
CVE-2026-31536 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandsmb: server: let send_done handle a completion without IB_SEND_SIGNALED
CVE-2026-31618 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandfbdev: tdfxfb: avoid divide-by-zero on FBIOPUT_VSCREENINFO
CVE-2026-31590 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandKVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION
CVE-2026-31667 ↗2026-04-26cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandInput: uinput - fix circular locking dependency with ff-core
CVE-2026-31593 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandKVM: SEV: Reject attempts to sync VMSA of an already-launched/encrypted vCPU
CVE-2026-31620 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandALSA: usx2y: us144mkii: fix NULL deref on missing interface 0
CVE-2026-31607 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0CriticalOut-of-bandusbip: validate number_of_packets in usbip_pack_ret_submit()
CVE-2026-31646 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: lan966x: fix page_pool error handling in lan966x_fdma_rx_alloc_page_pool()
CVE-2026-31606 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: f_hid: don't call cdev_init while cdev in use
CVE-2026-31555 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandfutex: Clear stale exiting pointer in futex_lock_pi() retry path
CVE-2026-31557 ↗2026-04-26azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandnvmet: move async event work off nvmet-wq
CVE-2026-31619 ↗2026-04-26azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ModerateOut-of-bandALSA: fireworks: bound device-supplied status before string array lookup
CVE-2026-41079 ↗2026-04-26cbl2 cups 2.3.3op2-11 on CBL Mariner 2.0ModerateOut-of-bandOpenPrinting CUPS: Heap out-of-bounds read in SNMP supply-level polling leaks stack memory to authenticated users
CVE-2025-13763 ↗2026-04-25azl3 opensc 0.26.1-1 on Azure Linux 3.0ModerateOut-of-bandLibopensc: opensc: multiple uses of uninitialized variable
CVE-2026-41205 ↗2026-04-25azl3 python-mako 1.2.4-2 on Azure Linux 3.0ImportantOut-of-bandMako: Path traversal via double-slash URI prefix in TemplateLookup
CVE-2026-23447 ↗2026-04-25cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandnet: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check
CVE-2026-23446 ↗2026-04-25cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: usb: aqc111: Do not perform PM inside suspend callback
CVE-2026-23439 ↗2026-04-25cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandudp_tunnel: fix NULL deref caused by udp_sock_create6 when CONFIG_IPV6=n
CVE-2026-23438 ↗2026-04-25cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet: mvpp2: guard flow control update with global_tx_fc in buffer switching
CVE-2026-23434 ↗2026-04-25cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandmtd: rawnand: serialize lock/unlock against other NAND operations
CVE-2026-23428 ↗2026-04-25cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandksmbd: fix use-after-free of share_conf in compound request
CVE-2026-6921 ↗2026-04-24Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-6921 Race in GPU
CVE-2026-6919 ↗2026-04-24Microsoft Edge for AndroidN/AOut-of-band0%Chromium: CVE-2026-6919 Use after free in DevTools
CVE-2026-41988 ↗2026-04-24azl3 uuid 1.6.2-51 on Azure Linux 3.0LowOut-of-band
CVE-2026-41989 ↗2026-04-24azl3 libgcrypt 1.10.3-1 on Azure Linux 3.0ModerateOut-of-band
CVE-2026-31531 ↗2026-04-24azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ModerateOut-of-bandipv4: nexthop: allocate skb dynamically in rtm_get_nexthop()
CVE-2026-31532 ↗2026-04-24azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandcan: raw: fix ro->uniq use-after-free in raw_rcv()
CVE-2026-21515 ↗2026-04-23Azure IOT CentralCriticalOut-of-band1%Azure IoT Central Elevation of Privilege Vulnerability
CVE-2026-24303 ↗2026-04-23Microsoft Partner CenterCriticalOut-of-band0%Microsoft Partner Center Elevation of Privilege Vulnerability
CVE-2026-26150 ↗2026-04-23Microsoft Purview eDiscoveryCriticalOut-of-band1%Microsoft Purview eDiscovery Elevation of Privilege Vulnerability
CVE-2026-32172 ↗2026-04-23Microsoft Power AppsCriticalOut-of-band0%Microsoft Power Apps Remote Code Execution Vulnerability
CVE-2026-32210 ↗2026-04-23Microsoft Dynamics 365 (online)CriticalOut-of-band1%Microsoft Dynamics 365 (online) Spoofing Vulnerability
CVE-2026-33102 ↗2026-04-23Microsoft 365 CopilotCriticalOut-of-band0%Microsoft 365 Copilot Elevation of Privilege Vulnerability
CVE-2026-33819 ↗2026-04-23Microsoft BingCriticalOut-of-band1%Microsoft Bing Remote Code Execution Vulnerability

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2025-61726CVSS 7.5multicluster engine for Kubernetes 2.9registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:0d311a96d10861ed390004216ef1ab7af16069752f93672a60a213d8a2352062_s390xPatch ↗Advisory ↗
Red HatCVE-2025-61728CVSS 7.5Red Hat Advanced Cluster Management for Kubernetes 2.15registry.redhat.io/rhacm2/volsync-rhel9@sha256:15a198e39cc0d139796a6cc9fa3bc0e6607776b0020f044452265e0868e44598_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-61729CVSS 7.5Red Hat Advanced Cluster Management for Kubernetes 2.15registry.redhat.io/rhacm2/volsync-rhel9@sha256:15a198e39cc0d139796a6cc9fa3bc0e6607776b0020f044452265e0868e44598_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-68121CVSS 7.4Red Hat OpenShift Builds 1.7.3registry.redhat.io/openshift-builds/openshift-builds-waiters-rhel9@sha256:153f9e059139e6dbaeb2e5166d21bfeec59a59aa5cd8045e11dbfa091479b4bb_amd64Patch ↗Advisory ↗
Red HatCVE-2025-68121CVSS 7.4multicluster engine for Kubernetes 2.9registry.redhat.io/multicluster-engine/discovery-rhel9@sha256:2780b7d0e3df764e906b02d76fc9bcc2142438427a0fa55b43b5a9ea6995e130_s390xPatch ↗Advisory ↗
Red HatCVE-2026-25639CVSS 7.5multicluster engine for Kubernetes 2.9registry.redhat.io/multicluster-engine/console-mce-rhel9@sha256:071331b4f2052e9a039942a79e224ff0cb41bc7763b1240ab83169a10c9eb34e_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-25679CVSS 7.5Red Hat OpenShift Builds 1.7.3registry.redhat.io/openshift-builds/openshift-builds-waiters-rhel9@sha256:153f9e059139e6dbaeb2e5166d21bfeec59a59aa5cd8045e11dbfa091479b4bb_amd64Patch ↗Advisory ↗
Red HatCVE-2026-25679CVSS 7.5Red Hat Enterprise Linux AppStream (v. 10)yggdrasil-0:0.4.8-4.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-27137CVSS 7.5Red Hat OpenShift Builds 1.7.3registry.redhat.io/openshift-builds/openshift-builds-waiters-rhel9@sha256:153f9e059139e6dbaeb2e5166d21bfeec59a59aa5cd8045e11dbfa091479b4bb_amd64Patch ↗Advisory ↗
Red HatCVE-2026-29063CVSS 8.8multicluster engine for Kubernetes 2.9registry.redhat.io/multicluster-engine/console-mce-rhel9@sha256:071331b4f2052e9a039942a79e224ff0cb41bc7763b1240ab83169a10c9eb34e_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-32282CVSS 7.8Red Hat Advanced Cluster Management for Kubernetes 2.15registry.redhat.io/rhacm2/volsync-rhel9@sha256:15a198e39cc0d139796a6cc9fa3bc0e6607776b0020f044452265e0868e44598_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Builds for Red Hat OpenShift 1.6.0registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:1c0d155195bfd251b40da10e153c8a738250f14253f337b198476740cb7bd81a_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Builds 1.7.3registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:190edd3effb60c56c885fc964d3eb48076293e1e43d745c4615ed00ef7daa145_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Advanced Cluster Management for Kubernetes 2.15registry.redhat.io/rhacm2/volsync-rhel9@sha256:15a198e39cc0d139796a6cc9fa3bc0e6607776b0020f044452265e0868e44598_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33211CVSS 9.6Builds for Red Hat OpenShift 1.6.0registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:1c0d155195bfd251b40da10e153c8a738250f14253f337b198476740cb7bd81a_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33211CVSS 9.6Red Hat OpenShift Builds 1.7.3registry.redhat.io/openshift-builds/openshift-builds-rhel9-operator@sha256:190edd3effb60c56c885fc964d3eb48076293e1e43d745c4615ed00ef7daa145_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33810CVSS 8.8Builds for Red Hat OpenShift 1.6.0registry.redhat.io/openshift-builds/openshift-builds-waiters-rhel9@sha256:71f49240685245565f35d7d4b6d7d55b442cb61bc7c0f4d25c5529ca9187ae9f_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33810CVSS 8.8Red Hat OpenShift Builds 1.7.3registry.redhat.io/openshift-builds/openshift-builds-waiters-rhel9@sha256:153f9e059139e6dbaeb2e5166d21bfeec59a59aa5cd8045e11dbfa091479b4bb_amd64Patch ↗Advisory ↗
Red HatCVE-2026-40175CVSS 9.0multicluster engine for Kubernetes 2.9registry.redhat.io/multicluster-engine/console-mce-rhel9@sha256:071331b4f2052e9a039942a79e224ff0cb41bc7763b1240ab83169a10c9eb34e_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-10911CVSS 5.5Red Hat Hardened Imageslibxslt-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2025-11731CVSS 3.1Red Hat Hardened Imageslibxslt-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2025-31133CVSS 8.2Red Hat Enterprise Linux AppStream AUS (v.8.6)aardvark-dns-2:1.0.1-40.module+el8.6.0+24209+25a14987.x86_64::container-tools:rhel8Patch ↗Advisory ↗
Red HatCVE-2025-47913CVSS 7.5Red Hat Enterprise Linux AppStream AUS (v.8.6)aardvark-dns-2:1.0.1-40.module+el8.6.0+24209+25a14987.x86_64::container-tools:rhel8Patch ↗Advisory ↗
Red HatCVE-2025-52565CVSS 8.2Red Hat Enterprise Linux AppStream AUS (v.8.6)aardvark-dns-2:1.0.1-40.module+el8.6.0+24209+25a14987.x86_64::container-tools:rhel8Patch ↗Advisory ↗
Red HatCVE-2025-52881CVSS 8.2Red Hat Enterprise Linux AppStream AUS (v.8.6)aardvark-dns-2:1.0.1-40.module+el8.6.0+24209+25a14987.x86_64::container-tools:rhel8Patch ↗Advisory ↗
Red HatCVE-2025-58183CVSS 7.5Red Hat Enterprise Linux AppStream AUS (v.8.6)aardvark-dns-2:1.0.1-40.module+el8.6.0+24209+25a14987.x86_64::container-tools:rhel8Patch ↗Advisory ↗
Red HatCVE-2025-65637CVSS 7.5Red Hat Enterprise Linux AppStream AUS (v.8.6)aardvark-dns-2:1.0.1-40.module+el8.6.0+24209+25a14987.x86_64::container-tools:rhel8Patch ↗Advisory ↗
Red HatCVE-2025-7424CVSS 7.5Red Hat Hardened Imageslibxslt-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-25679CVSS 7.5Red Hat Advanced Cluster Security 4.8registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:5804b537b255c13107f7ab6d48b445c4210f4274e19a011d37b3302b35a965e5_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-27140CVSS 9.0Red Hat Enterprise Linux AppStream (v. 8)delve-0:1.25.2-1.module+el8.10.0+23746+9db33b5e.aarch64::go-toolset:rhel8Patch ↗Advisory ↗
Red HatCVE-2026-27143CVSS 8.1Red Hat Enterprise Linux AppStream (v. 8)delve-0:1.25.2-1.module+el8.10.0+23746+9db33b5e.aarch64::go-toolset:rhel8Patch ↗Advisory ↗
Red HatCVE-2026-27144CVSS 8.1Red Hat Enterprise Linux AppStream (v. 8)delve-0:1.25.2-1.module+el8.10.0+23746+9db33b5e.aarch64::go-toolset:rhel8Patch ↗Advisory ↗
Red HatCVE-2026-29063CVSS 8.8Red Hat Advanced Cluster Security 4.8registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:190480aab6dcffb2c38cb6476f7ee1f153deeb88d9084f6fe40d1e9b23c372f5_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-29063CVSS 8.8Red Hat Advanced Cluster Security 4.8registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:5804b537b255c13107f7ab6d48b445c4210f4274e19a011d37b3302b35a965e5_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-32280CVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)delve-0:1.25.2-1.module+el8.10.0+23746+9db33b5e.aarch64::go-toolset:rhel8Patch ↗Advisory ↗
Red HatCVE-2026-32282CVSS 7.8Red Hat Enterprise Linux AppStream (v. 8)delve-0:1.25.2-1.module+el8.10.0+23746+9db33b5e.aarch64::go-toolset:rhel8Patch ↗Advisory ↗
Red HatCVE-2026-32283CVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)delve-0:1.25.2-1.module+el8.10.0+23746+9db33b5e.aarch64::go-toolset:rhel8Patch ↗Advisory ↗
Red HatCVE-2026-32286CVSS 7.5Red Hat Advanced Cluster Security 4.8registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:190480aab6dcffb2c38cb6476f7ee1f153deeb88d9084f6fe40d1e9b23c372f5_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-32286CVSS 7.5Red Hat Advanced Cluster Security 4.8registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:5804b537b255c13107f7ab6d48b445c4210f4274e19a011d37b3302b35a965e5_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Enterprise Linux AppStream EUS (v.9.6)rhc-1:0.2.7-1.el9_6.3.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Enterprise Linux AppStream (v. 9)rhc-1:0.2.7-4.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Advanced Cluster Security 4.8registry.redhat.io/advanced-cluster-security/rhacs-scanner-rhel8@sha256:030180ba7545abfcb87c1e777889d1e23dc44e8e8fb1dbe1ab271ad9f5a4c5b9_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Advanced Cluster Security 4.8registry.redhat.io/advanced-cluster-security/rhacs-scanner-rhel8@sha256:030180ba7545abfcb87c1e777889d1e23dc44e8e8fb1dbe1ab271ad9f5a4c5b9_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33815CVSS 8.3Red Hat Advanced Cluster Security 4.8registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:190480aab6dcffb2c38cb6476f7ee1f153deeb88d9084f6fe40d1e9b23c372f5_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33815CVSS 8.3Red Hat Advanced Cluster Security 4.8registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:5804b537b255c13107f7ab6d48b445c4210f4274e19a011d37b3302b35a965e5_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33816CVSS 8.3Red Hat Advanced Cluster Security 4.8registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:190480aab6dcffb2c38cb6476f7ee1f153deeb88d9084f6fe40d1e9b23c372f5_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33816CVSS 8.3Red Hat Advanced Cluster Security 4.8registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:5804b537b255c13107f7ab6d48b445c4210f4274e19a011d37b3302b35a965e5_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-34986CVSS 7.5Red Hat Advanced Cluster Security 4.8registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:190480aab6dcffb2c38cb6476f7ee1f153deeb88d9084f6fe40d1e9b23c372f5_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-34986CVSS 7.5Red Hat Advanced Cluster Security 4.8registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:5804b537b255c13107f7ab6d48b445c4210f4274e19a011d37b3302b35a965e5_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-35469CVSS 6.5Red Hat Advanced Cluster Security 4.8registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:0085ef40238991f5845e814b8af029bae0f86df2b1267db1fc7b183e153261f6_amd64Patch ↗Advisory ↗
Red HatCVE-2026-35469CVSS 6.5Red Hat Advanced Cluster Security 4.8registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:3290bf6033dffb72084afd9eb038f0268b76ea1112121e587da172d7cd432e68_arm64Patch ↗Advisory ↗
Red HatCVE-2026-41080CVSS 3.7Red Hat Hardened Imagesexpat-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-5958CVSS 6.3Red Hat Hardened Imagessed-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2025-61729CVSS 7.5Red Hat OpenShift AI 2.25registry.redhat.io/rhoai/odh-llm-d-inference-scheduler-rhel9@sha256:70712c14b09d38efa09b8bd26980d3e0c68dc3ab14b32e8a553286ef05614d72_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift AI 2.25registry.redhat.io/rhoai/odh-mm-rest-proxy-rhel9@sha256:5be8977599e99ff5828eff59ad5d9ea5d0f2d99115b5e99d31df9469fb8ea912_amd64Patch ↗Advisory ↗
Red HatCVE-2026-27140CVSS 9.0Red Hat Enterprise Linux AppStream (v. 9)go-toolset-0:1.25.9-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-27143CVSS 8.1Red Hat Enterprise Linux AppStream (v. 9)go-toolset-0:1.25.9-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-27144CVSS 8.1Red Hat Enterprise Linux AppStream (v. 9)go-toolset-0:1.25.9-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32280CVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)go-toolset-0:1.25.9-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9Red Hat Enterprise Linux AppStream (v. 9)go-toolset-0:1.25.9-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32282CVSS 7.8Red Hat Enterprise Linux AppStream (v. 9)go-toolset-0:1.25.9-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32283CVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)go-toolset-0:1.25.9-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-34986CVSS 7.5Red Hat Enterprise Linux AppStream (v. 9)buildah-2:1.41.8-3.el9_7.aarch64Patch ↗Advisory ↗