CYBERSECURITYTRACKER
TRACKING8,337 stories in this site build1,874 vulnerability news stories in this site build
Vulnerabilities

May 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 3 vulnerabilities with exploitation detected in the wild this month. This defender-focused view covers 1,840 vulnerabilities across 5,089 returned patch records from 5 vendors. Filter the complete month, or browse the static page trail without JavaScript.

5,089all patch recordsClear filters155criticalShow these records3Microsoft exploitation detectedShow these records4Microsoft in the Known Exploited Vulnerabilities catalogShow these records3,260tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

My Stack only keeps records whose vendor you have pinned. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 1 of 26 · records 1 to 200 of 5,089

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-42897 ↗Microsoft Exchange Server 2016 Cumulative Update 23CriticalOut-of-band1%Microsoft rates: Exploitation DetectedCISA KEVVulnCheckENISAKB5094139KB5094140
and 2 moreKB5094142KB5094144
2 mentionsMicrosoft Exchange Server Spoofing Vulnerability
CVE-2026-41091 ↗Microsoft Malware Protection EngineImportantOut-of-band0%Microsoft rates: Exploitation DetectedPublicly disclosedCISA KEVVulnCheckENISA1 mentionsMicrosoft Defender Elevation of Privilege Vulnerability
CVE-2026-45498 ↗Microsoft Defender Antimalware PlatformLowOut-of-band1%Microsoft rates: Exploitation DetectedPublicly disclosedCISA KEVVulnCheckENISA1 mentionsMicrosoft Defender Denial of Service Vulnerability
CVE-2026-45659 ↗Microsoft SharePoint Enterprise Server 2016ImportantOut-of-band3%Microsoft rates: Exploitation Less LikelyCISA KEVVulnCheckENISAKB5002863KB5002868
and 1 moreKB5002870
5 mentionsMicrosoft SharePoint Remote Code Execution Vulnerability
CVE-2026-8450 ↗azl3 perl-HTTP-Daemon 6.16-1 on Azure Linux 3.0CriticalOut-of-band3%Microsoft rating unavailableHTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()
CVE-2026-7374 ↗azl3 kubevirt 1.7.1-2 on Azure Linux 3.0CriticalOut-of-band1%Microsoft rating unavailableKubevirt: kubevirt virt-handler: privilege escalation and node compromise via symlink following vulnerability
CVE-2026-46595 ↗azl3 docker-buildx 0.14.0-11 on Azure Linux 3.0CriticalOut-of-band1%Microsoft rating unavailableInvoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh
CVE-2026-39831 ↗azl3 cert-manager 1.12.15-6 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailableInvoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh
CVE-2026-39821 ↗azl3 application-gateway-kubernetes-ingress 1.7.7-3 on Azure Linux 3.0CriticalOut-of-band1%Microsoft rating unavailableInvoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
CVE-2026-23652 ↗Microsoft Power PagesCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Power Pages Remote Code Execution Vulnerability
CVE-2026-23663 ↗Microsoft Global Secure Access (GSA)CriticalOut-of-band1%Microsoft rates: N/AMicrosoft Global Secure Access (GSA) Information Disclosure Vulnerability
CVE-2026-26147 ↗Azure Stack HCICriticalOut-of-band1%Microsoft rates: N/AAzure Stack HCI Information Disclosure Vulnerability
CVE-2026-33843 ↗Microsoft Entra IDCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Azure Active Directory B2C Elevation of Privilege Vulnerability
CVE-2026-35430 ↗Azure Privileged Identity Management (PIM)CriticalOut-of-band1%Microsoft rates: N/AAzure Privileged Identity Management (PIM) Elevation of Privilege Vulnerability
CVE-2026-40411 ↗Azure Virtual Network GatewayCriticalOut-of-band1%Microsoft rates: N/AAzure Virtual Network Gateway Remote Code Execution Vulnerability
CVE-2026-40412 ↗Azure Orbital SpatioCriticalOut-of-band1%Microsoft rates: N/AAzure Orbital Spatio Remote Code Execution Vulnerability
CVE-2026-41090 ↗Microsoft 365 Copilot for iOSCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Copilot Tampering Vulnerability
CVE-2026-41104 ↗Microsoft Planetary Computer Pro (GeoCatalog)CriticalOut-of-band2%Microsoft rates: N/AMicrosoft Planetary Computer Pro Information Disclosure Vulnerability
CVE-2026-42827 ↗Microsoft 365 CopilotCriticalOut-of-band1%Microsoft rates: N/AM365 Copilot Information Disclosure Vulnerability
CVE-2026-42901 ↗Microsoft Entra IDCriticalOut-of-band0%Microsoft rates: N/AMicrosoft Entra ID Elevation of Privilege Vulnerability
CVE-2026-47280 ↗Azure Resource ManagerCriticalOut-of-band1%Microsoft rating unavailableAzure Resource Manager Elevation of Privilege Vulnerability
CVE-2026-33278 ↗azl3 unbound 1.19.1-5 on Azure Linux 3.0CriticalOut-of-band1%Microsoft rating unavailablePossible arbitrary code execution during DNSSEC validation
CVE-2026-45584 ↗Microsoft Malware Protection EngineCriticalOut-of-band1%Microsoft rating unavailableMicrosoft Defender Remote Code Execution Vulnerability
CVE-2026-42822 ↗Azure LocalCriticalOut-of-band1%Microsoft rates: Exploitation More LikelyAzure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability
CVE-2026-42945 ↗azl3 nginx 1.28.3-1 on Azure Linux 3.0CriticalOut-of-band3%Microsoft rating unavailableVulnCheck1 mentionsNGINX ngx_http_rewrite_module vulnerability
CVE-2026-41615 ↗Microsoft Authenticator for AndroidCriticalOut-of-band1%Microsoft rates: Exploitation Less LikelyMicrosoft Authenticator Information Disclosure Vulnerability
CVE-2026-32161 ↗Windows 10 Version 1809 for 32-bit SystemsCritical0%Microsoft rates: Exploitation Less LikelyKB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Native WiFi Miniport Driver Remote Code Execution Vulnerability
CVE-2026-35421 ↗Windows 10 Version 1809 for 32-bit SystemsCritical0%Microsoft rates: Exploitation UnlikelyKB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows GDI Remote Code Execution Vulnerability
CVE-2026-40358 ↗Microsoft Office 2019 for 32-bit editionsCritical0%Microsoft rates: Exploitation Less LikelyKB5002866Microsoft Office Remote Code Execution Vulnerability
CVE-2026-40361 ↗Microsoft Office 2019 for 32-bit editionsCritical0%Microsoft rates: Exploitation More LikelyKB5002858Microsoft Outlook and Word Remote Code Execution Vulnerability
CVE-2026-40363 ↗Microsoft Office 2019 for 32-bit editionsCritical0%Microsoft rates: Exploitation Less LikelyKB5002866Microsoft Office Remote Code Execution Vulnerability
CVE-2026-40364 ↗Microsoft Office 2019 for 32-bit editionsCritical0%Microsoft rates: Exploitation More LikelyKB5002858Microsoft Word Remote Code Execution Vulnerability
CVE-2026-40365 ↗Microsoft SharePoint Enterprise Server 2016Critical1%Microsoft rates: Exploitation Less LikelyKB5002863KB5002868
and 1 moreKB5002870
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-40366 ↗Microsoft Office 2019 for 32-bit editionsCritical0%Microsoft rates: Exploitation Less LikelyKB5002858Microsoft Word Remote Code Execution Vulnerability
CVE-2026-40367 ↗Microsoft SharePoint Enterprise Server 2016Critical0%Microsoft rates: Exploitation UnlikelyKB5002858KB5002863
and 4 moreKB5002868KB5002869KB5002870KB5002872
Microsoft Word Remote Code Execution Vulnerability
CVE-2026-40402 ↗Windows Server 2022Critical0%Microsoft rates: Exploitation Less LikelyKB5087420KB5087424
and 2 moreKB5087545KB5093998
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2026-40403 ↗Windows 10 Version 1809 for 32-bit SystemsCritical0%Microsoft rates: Exploitation Less LikelyKB5087420KB5087423
and 14 moreKB5087424KB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087544KB5087545KB5089466KB5089548KB5089549KB5093998KB5094127
Windows Graphics Component Remote Code Execution Vulnerability
CVE-2026-41089 ↗Windows Server 2019Critical1%Microsoft rates: Exploitation Less LikelyVulnCheckKB5087423KB5087424
and 7 moreKB5087470KB5087471KB5087537KB5087538KB5087539KB5087541KB5087545
Windows Netlogon Remote Code Execution Vulnerability
CVE-2026-41096 ↗Windows Server 2025 (Server Core installation)Critical1%Microsoft rates: Exploitation UnlikelyKB5087420KB5087423
and 6 moreKB5087539KB5087541KB5089466KB5089548KB5089549KB5093998
Windows DNS Client Remote Code Execution Vulnerability
CVE-2026-41103 ↗Microsoft JIRA SAML SSO pluginCritical1%Microsoft rates: Exploitation More LikelyMicrosoft SSO Plugin for Jira & Confluence Elevation of Privilege Vulnerability
CVE-2026-42831 ↗Microsoft Office LTSC for Mac 2021Critical0%Microsoft rates: Exploitation UnlikelyMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-42898 ↗Microsoft Dynamics 365 (on-premises) version 9.1Critical1%Microsoft rates: Exploitation UnlikelyKB5078943Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
CVE-2026-31718 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0CriticalOut-of-band1%Microsoft rating unavailableksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger
CVE-2026-26129 ↗Microsoft 365 Copilot's Business ChatCriticalOut-of-band1%Microsoft rates: N/AM365 Copilot Information Disclosure Vulnerability
CVE-2026-26164 ↗Microsoft 365 Copilot's Business ChatCriticalOut-of-band1%Microsoft rates: Exploitation Less LikelyM365 Copilot Information Disclosure Vulnerability
CVE-2026-32207 ↗Azure Machine LearningCriticalOut-of-band1%Microsoft rating unavailableAzure Machine Learning Notebook Spoofing Vulnerability
CVE-2026-33109 ↗Azure Managed Instance for Apache CassandraCriticalOut-of-band1%Microsoft rates: N/AAzure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
CVE-2026-33111 ↗Copilot Chat (Microsoft Edge)CriticalOut-of-band1%Microsoft rates: Exploitation Less LikelyCopilot Chat (Microsoft Edge) Information Disclosure Vulnerability
CVE-2026-33821 ↗Dynamics 365 Customer InsightsCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Dynamics 365 Customer Insights Elevation of Privilege Vulnerability
CVE-2026-33823 ↗Microsoft TeamsCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Team Events Portal Information Disclosure Vulnerability
CVE-2026-33844 ↗Azure Managed Instance for Apache CassandraCriticalOut-of-band1%Microsoft rates: N/AAzure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
CVE-2026-34327 ↗Microsoft Partner CenterCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Partner Center Spoofing Vulnerability
CVE-2026-35428 ↗Azure Cloud ShellCriticalOut-of-band1%Microsoft rates: N/AAzure Cloud Shell Spoofing Vulnerability
CVE-2026-35435 ↗Azure AI FoundryCriticalOut-of-band1%Microsoft rates: Exploitation More LikelyAzure AI Foundry Elevation of Privilege Vulnerability
CVE-2026-40379 ↗Microsoft Entra IDCriticalOut-of-band1%Microsoft rates: N/AAzure Entra ID Spoofing Vulnerability
CVE-2026-41105 ↗Azure Monitor Action Group notification systemCriticalOut-of-band1%Microsoft rates: N/AAzure Monitor Action Group Notification System Elevation of Privilege Vulnerability
CVE-2026-42826 ↗Azure DevOpsCriticalOut-of-band1%Microsoft rates: N/AAzure DevOps Information Disclosure Vulnerability
CVE-2026-31705 ↗azl3 kernel 6.6.134.1-2 on Azure Linux 3.0CriticalOut-of-band1%Microsoft rating unavailableksmbd: fix out-of-bounds write in smb2_get_ea() EA alignment
CVE-2025-71305 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailabledrm/display/dp_mst: Add protection against 0 vcpi
CVE-2026-45899 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableext4: drop extent cache when splitting extent fails
CVE-2026-6722 ↗azl3 php 8.3.29-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableUse-After-Free in SOAP using Apache map
CVE-2026-48526 ↗azl3 python-jwt 2.8.0-2 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablePyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed
CVE-2026-48959 ↗azl3 perl 5.38.2-509 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableIO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward
CVE-2026-40034 ↗azl3 rust 1.75.0-29 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablegitoxide - Command Injection via Partial .gitmodules Override in gix-submodule
CVE-2026-48962 ↗azl3 perl 5.38.2-509 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableIO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob
CVE-2026-48864 ↗azl3 libsolv 0.7.28-3 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableLibsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
CVE-2026-9804 ↗azl3 kubevirt 1.7.1-8 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableKubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read
CVE-2026-42012 ↗azl3 gnutls 3.8.3-8 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableGnutls: gnutls: certificate validation bypass due to improper handling of uri and srv sans
CVE-2026-5260 ↗azl3 gnutls 3.8.3-8 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableGnutls: gnutls: information disclosure via heap overread in rsa key exchange
CVE-2026-42013 ↗azl3 gnutls 3.8.3-8 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableGnutls: gnutls: certificate validation bypass due to oversized subject alternative name
CVE-2026-46242 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailable2 mentionseventpoll: fix ep_remove struct eventpoll / struct file UAF
CVE-2026-47294 ↗Microsoft SharePoint Enterprise Server 2016ImportantOut-of-band1%Microsoft rates: Exploitation Less LikelyKB5002863KB5002868
and 1 moreKB5002870
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2026-9538 ↗azl3 perl 5.38.2-509 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableArchive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header
CVE-2026-42496 ↗azl3 perl 5.38.2-509 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableArchive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory
CVE-2026-46150 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablefanotify: fix false positive on permission events
CVE-2026-46191 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablefbcon: Avoid OOB font access if console rotation fails
CVE-2026-45956 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailabledrm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl()
CVE-2026-45942 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableext4: fix e4b bitmap inconsistency reports
CVE-2026-45958 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailabledrm/exynos: vidi: fix to avoid directly dereferencing user pointer

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-csi-driver-nfs-rhel9@sha256:7d1f571b87ba1e197285c78a78ac4dcffa55ac4e6382ecf10ed630abd02e4df0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-sriov-network-config-daemon-rhel9@sha256:a38d8ed8b5ea31126b1f2238db1e790ea01a154949187bfe355c21a76f789462_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9@sha256:0b165040657b16770b52a0cde7be46db0d6410e6d502b11e7b6053f9ad441c49_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-operator-bundle@sha256:f4100f181620f5424e66633dbdd3c7402c8db75f93c54fe092ff2301d8dd0015_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33211trackedCVSS 9.6Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9@sha256:0b165040657b16770b52a0cde7be46db0d6410e6d502b11e7b6053f9ad441c49_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33211trackedCVSS 9.6Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-operator-bundle@sha256:f4100f181620f5424e66633dbdd3c7402c8db75f93c54fe092ff2301d8dd0015_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.16microshift-0:4.16.63-202605251227.p0.g1133ac0.assembly.4.16.63.el9.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Multicluster Global Hub 1.5.8registry.redhat.io/multicluster-globalhub/multicluster-globalhub-agent-rhel9@sha256:62b308e48b973c04509efc66de4cdf11acc729625b75f86bab27de82a7230d14_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.19registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:02d39c48c3ecaaea7d6d3854845c498b53f2ef644d83c2c662f2ac15fc9ad907_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.19registry.redhat.io/openshift4/ose-aws-efs-csi-driver-container-rhel9@sha256:79246f9cf97c2dcbcb41bf61c07d9dedb9e99ea87af071c685c12c035f1035ee_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.19microshift-0:4.19.32-202605212036.p0.g27d51c3.assembly.4.19.32.el9.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Cryostat 4 on RHEL 9cryostat/cryostat-grafana-dashboard-rhel9@sha256:8270ad1bdb5394e463b8f688fe39adbfd3177881f3a3ed0e188f5acd07b12747_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.21registry.redhat.io/openshift4/ose-aws-ebs-csi-driver-rhel9@sha256:051fe1b7a40fa21e8e84db4d984748f8c9bd6507904a738778ba3ea2c8fc05a4_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.21registry.redhat.io/openshift4/ose-aws-efs-csi-driver-container-rhel9@sha256:b7d56d9687b95c08a7f36ef1fc338fd74d2c070bb8e57f0814617f375042e0b0_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift GitOps 1.19registry.redhat.io/openshift-gitops-1/argocd-image-updater-rhel8@sha256:021a2b93438ab7a0cdb1ee15ce32c38cccb556802203b7f79604b21fde0dfe38_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift GitOps 1.18registry.redhat.io/openshift-gitops-1/dex-rhel8@sha256:45982222d809b7e77adf13a750f5e5dca63aa0240d76b7d496f1e2676f71c87f_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Quay 3.14registry.redhat.io/quay/quay-rhel8@sha256:4ae7d2d72a2370bd5401f570e21386bc9a6df0b145030060c922fcf754c7839b_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33210trackedCVSS 9.1Red Hat Enterprise Linux AppStream (v. 9)ruby-0:4.0.3-32.module+el9.8.0+24280+122d8796.aarch64::ruby:4.0Patch ↗Advisory ↗
Red HatCVE-2026-33210trackedCVSS 9.1Red Hat Enterprise Linux AppStream (v. 10)ruby4.0-0:4.0.3-34.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-7374trackedCVSS 9.9Red Hat Container Native Virtualization 4.21registry.redhat.io/container-native-virtualization/virt-handler-rhel9@sha256:269847ed93e9213f9295c7ce9da76ccdbe5812d87d86485167025145e374ca69_amd64Patch ↗Advisory ↗
Red HatCVE-2026-7374trackedCVSS 9.9Red Hat Container Native Virtualization 4.18registry.redhat.io/container-native-virtualization/virt-handler-rhel9@sha256:2182b286267298b951fe96e36abb05de59dc6569b9633e31ce5ec1354f30aeae_amd64Patch ↗Advisory ↗
Red HatCVE-2026-7374trackedCVSS 9.9Red Hat Container Native Virtualization 4.17registry.redhat.io/container-native-virtualization/virt-handler-rhel9@sha256:72cf5ccb119c366afd5e03cd30896520c904a6a5185763023a2cb0dbe51781d8_arm64Patch ↗Advisory ↗
Red HatCVE-2026-7374trackedCVSS 9.9Red Hat Container Native Virtualization 4.19registry.redhat.io/container-native-virtualization/virt-handler-rhel9@sha256:2684c4c10aa7f81d79ade6808a862fafdc58ff00f8b3b331b7b777fc73de537d_amd64Patch ↗Advisory ↗
Red HatCVE-2026-7374trackedCVSS 9.9Red Hat Container Native Virtualization 4.20registry.redhat.io/container-native-virtualization/virt-handler-rhel9@sha256:0136aaa20934175d763c6b5ddf24ebd90e8a7e4510a6517c60705d96ae6c5149_s390xPatch ↗Advisory ↗
Red HatCVE-2026-7374trackedCVSS 9.9Red Hat Container Native Virtualization 4.12registry.redhat.io/container-native-virtualization/virt-handler@sha256:14d2ab487872ac2180a6bf413703d124e5a66063222712e0b0693d120414512d_amd64Patch ↗Advisory ↗
Red HatCVE-2026-7374trackedCVSS 9.9Red Hat Container Native Virtualization 4.15registry.redhat.io/container-native-virtualization/virt-handler-rhel9@sha256:150e16ca964b4afd80b41d0ec2f3551e31ed6f18e07aaa91b49c39312a10c799_arm64Patch ↗Advisory ↗
Red HatCVE-2026-7374trackedCVSS 9.9Red Hat Container Native Virtualization 4.13registry.redhat.io/container-native-virtualization/virt-handler-rhel9@sha256:496bb7164546ea472905bc301a8a4ae9194ec0b300ae847c30bb5a775af5d546_amd64Patch ↗Advisory ↗
Red HatCVE-2026-7374trackedCVSS 9.9Red Hat Container Native Virtualization 4.14registry.redhat.io/container-native-virtualization/virt-handler-rhel9@sha256:136f6df755b01ebc36a1d395b9afa45d3f8100bcdee95e9ead614bb6795348d0_arm64Patch ↗Advisory ↗
Red HatCVE-2026-7374trackedCVSS 9.9Red Hat Container Native Virtualization 4.16registry.redhat.io/container-native-virtualization/virt-handler-rhel9@sha256:3f39822dbf9a5ad965f4e09b66ad4319c95e38492095e1a5265033d3d245c060_amd64Patch ↗Advisory ↗
CiscoCVE-2026-20223trackedCVSS 10.0Cisco Secure Workload1.102Patch ↗Advisory ↗
Red HatCVE-2026-22778trackedCVSS 9.8Red Hat OpenShift AI 3.3registry.redhat.io/rhoai/odh-vllm-cpu-rhel9@sha256:6e7c80ca248eb60192b65f5209efecbfb1467ed884899f34fe8a60ea1e9cd5dd_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/ose-csi-driver-nfs-rhel9@sha256:b1700eb1f2dacd9b9c8f682891180dc83f876390d0c386c0bcf3778ee2aa7eac_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.20registry.redhat.io/openshift4/azure-service-rhel9-operator@sha256:2007fc6d424e2075b80f2a987cd0ae65fd38ae02865aafddd4d5605aa3460474_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.17registry.redhat.io/openshift4/kube-metrics-server-rhel9@sha256:0d9d982295f7e40a8117ae0e37507718c8fbddecbab6d8d168fba7b8c40d9d04_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.17registry.redhat.io/openshift4/ose-sriov-network-device-plugin-rhel9@sha256:2a70c8d6b2f7ee2030b48c0a405a79b3c66183338a4552b94970cf8ea531b96f_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.18microshift-0:4.18.42-202605181217.p0.gf4eeb37.assembly.4.18.42.el9.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift AI 3.3registry.redhat.io/rhoai/odh-kube-auth-proxy-rhel9@sha256:0e360eae488f4e2515221476aeffeb591f40d44b97177f51803449d8f3d61e7a_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Enterprise Linux AppStream EUS (v. 10.0)opentelemetry-collector-0:0.144.0-2.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Enterprise Linux AppStream EUS (v.9.6)opentelemetry-collector-0:0.144.0-2.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Enterprise Linux AppStream EUS (v.9.4)opentelemetry-collector-0:0.144.0-2.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33454trackedCVSS 9.4Red Hat Build of Apache Camel 4.14 for Quarkus 3.27Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-40453trackedCVSS 9.9Red Hat Build of Apache Camel 4.14 for Quarkus 3.27Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-27962trackedCVSS 9.1Red Hat Quay 3.16registry.redhat.io/quay/quay-rhel9@sha256:139cae64e4790ebf8b760c6376a33d15233222a25e4da39c6062d7e46c3a1bef_amd64Patch ↗Advisory ↗
Red HatCVE-2026-28802trackedCVSS 9.1Red Hat Quay 3.16registry.redhat.io/quay/quay-rhel9@sha256:139cae64e4790ebf8b760c6376a33d15233222a25e4da39c6062d7e46c3a1bef_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.21registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:15d899f50080b793865170add60d8f1a75c720fbee60a15005d6791af9664176_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.21registry.redhat.io/openshift4/ose-cluster-nfd-rhel9-operator@sha256:55af6d0b6f04aae9227108d33af2589ec2b08def27b0a96bbd8cf5dcd96a0b34_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1multicluster engine for Kubernetes 2.9registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel9@sha256:16dddebe90650a5d8a0d3c10357c7d0a094920889921befb9a52d9377493c5f4_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1multicluster engine for Kubernetes 2.10registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel9@sha256:055922c629f46db60d21bc850a65eff3e1dd8cb2428591d464c6a9f5cfb97951_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1multicluster engine for Kubernetes 2.11registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel9@sha256:58bd75f698338aab4cc8c04e28530368dece860c4741f8a2926f72726671e8e1_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1multicluster engine for Kubernetes 2.9registry.redhat.io/multicluster-engine/cluster-proxy-addon-rhel9@sha256:9382c0cf93d5bfc0e844aeacb5507aefa8b6358bf3c211890adc5a78878140d5_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Enterprise Linux AppStream (v. 10)opentelemetry-collector-0:0.144.0-2.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Enterprise Linux AppStream (v. 9)rhc-1:0.2.7-5.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Enterprise Linux AppStream (v. 9)opentelemetry-collector-0:0.144.0-2.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Quay 3.16registry.redhat.io/quay/quay-rhel9@sha256:139cae64e4790ebf8b760c6376a33d15233222a25e4da39c6062d7e46c3a1bef_amd64Patch ↗Advisory ↗
Red HatCVE-2026-4599trackedCVSS 9.1Red Hat Quay 3.16registry.redhat.io/quay/quay-rhel9@sha256:139cae64e4790ebf8b760c6376a33d15233222a25e4da39c6062d7e46c3a1bef_amd64Patch ↗Advisory ↗
Red HatCVE-2026-4599trackedCVSS 9.1Migration Toolkit for Virtualization 2.1registry.redhat.io/migration-toolkit-virtualization/mtv-console-plugin-rhel9@sha256:0b1a46357b43429aa2729b7caa728969a0d2cf306f56cbf3607acb78ac95b099_amd64Patch ↗Advisory ↗
Red HatCVE-2026-4599trackedCVSS 9.1Migration Toolkit for Virtualization 2.9registry.redhat.io/migration-toolkit-virtualization/mtv-console-plugin-rhel9@sha256:ac92e8f85699adfd5517fa9bbeb34833a4f9f9b0ccbfa3a55c0d9822976dadfc_amd64Patch ↗Advisory ↗
Red HatCVE-2026-27446trackedCVSS 9.1Red Hat JBoss EAP 8.1 for RHEL 8eap8-activemq-artemis-0:2.40.0-6.redhat_00012.1.el8eap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-27446trackedCVSS 9.1Red Hat JBoss EAP 8.1 for RHEL 9eap8-activemq-artemis-0:2.40.0-6.redhat_00012.1.el9eap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-27446trackedCVSS 9.1Red Hat JBoss Enterprise Application Platform 8.1.7.GAorg.apache.activemq.artemis-server-2.40.0.redhat-00015.jarPatch ↗Advisory ↗
CiscoCVE-2026-20182trackedCVSS 10.0Cisco Catalyst SD-WAN17.2Patch ↗Advisory ↗
Red HatCVE-2026-27446trackedCVSS 9.1Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1multicluster engine for Kubernetes 2.6registry.redhat.io/multicluster-engine/assisted-installer-agent-rhel8@sha256:04a8dd280a134d768f6818aa2d2af3ba9ad8f6d2226d536f763f2df3fb4816d8_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33454trackedCVSS 9.4Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-40453trackedCVSS 9.9Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-41635trackedCVSS 9.8Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-27140trackedCVSS 9.0Red Hat Enterprise Linux AppStream E4S (v.8.8)delve-0:1.9.1-1.module+el8.8.0+16778+5fbb74f5.src::go-toolset:rhel8Patch ↗Advisory ↗
Red HatCVE-2026-27140trackedCVSS 9.0Red Hat Enterprise Linux AppStream AUS (v.8.6)delve-0:1.7.2-1.module+el8.6.0+12972+ebab5911.src::go-toolset:rhel8Patch ↗Advisory ↗
Red HatCVE-2026-27140trackedCVSS 9.0Red Hat Enterprise Linux AppStream AUS (v.8.4)delve-0:1.5.0-2.module+el8.4.0+8864+58b0fcdb.src::go-toolset:rhel8Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.15registry.redhat.io/openshift4/ose-sriov-network-device-plugin-rhel9@sha256:2203b3d33eb5908f8989970788a214469d29588924d48670b5a12f0f43334233_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1multicluster engine for Kubernetes 2.8registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel9@sha256:2157410769cc1243e3396847f32ad03eadb6bdf4693cf14d332e55afd9a107e1_s390xPatch ↗Advisory ↗
Red HatCVE-2026-27140trackedCVSS 9.0Red Hat Enterprise Linux AppStream E4S (v.9.0)golang-0:1.17.13-12.el9_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-27140trackedCVSS 9.0Red Hat Enterprise Linux AppStream EUS (v.9.4)go-toolset-0:1.21.13-16.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-27140trackedCVSS 9.0Red Hat Enterprise Linux AppStream E4S (v.9.2)golang-0:1.19.13-25.el9_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.14registry.redhat.io/openshift4/ose-sriov-network-device-plugin@sha256:07ceb33add8664b2ed5a4135f47d21e6e3a8cb0347dddeb69245540c97f5b15e_amd64Patch ↗Advisory ↗
Red HatCVE-2026-27140trackedCVSS 9.0Red Hat Enterprise Linux AppStream EUS (v.9.6)go-toolset-0:1.25.9-1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-27140trackedCVSS 9.0Red Hat Enterprise Linux AppStream EUS (v. 10.0)go-toolset-0:1.25.9-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/ose-powervs-block-csi-driver-rhel9-operator@sha256:915ceff6d73dd9c552e961db39a6dfc6c42fb35711833911595ecf67321266a4_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/ose-local-storage-mustgather-rhel9@sha256:377cf0a041ed83dc3c21078b152842412c4e995c9194b40930baaf3c4ccf10e3_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.12registry.redhat.io/openshift4/ose-sriov-network-device-plugin@sha256:3ba68ff7f848a6118338e57d10cea4e128d47ebc4889ca5db8fe99ab758e4fab_amd64Patch ↗Advisory ↗
SuseCVE-2025-15467trackedCVSS 9.8SUSE Linux Enterprise Server 16.0openssl-3-x86_64-v3-livepatches-0:0.3-160000.1.1.x86_64no patch linkAdvisory ↗
Red HatCVE-2026-29186trackedCVSS 9.1Red Hat Developer Hub 1.9registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:80453720616cee369e9f79863ef1815a2741afdeb25d3572085d11ad54afa9a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Advanced Cluster Security 4.9registry.redhat.io/advanced-cluster-security/rhacs-scanner-rhel8@sha256:093c816ee564a4192c965d723977060cc17ad9f88060c093c183c3e22860ac2d_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Advanced Cluster Security for Kubernetes 4.10registry.redhat.io/advanced-cluster-security/rhacs-scanner-v4-rhel8@sha256:28eff2a215687431483d5d586a66998f2a8b3606d711d4e15c0cbb6360818a5d_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33228trackedCVSS 9.8Red Hat Developer Hub 1.9registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:80453720616cee369e9f79863ef1815a2741afdeb25d3572085d11ad54afa9a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-27606trackedCVSS 9.1Red Hat Ansible Automation Platform 2.6 for RHEL 9automation-platform-ui-0:2.6.8-1.el9ap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-27606trackedCVSS 9.1Red Hat Ansible Automation Platform 2.5 for RHEL 8automation-gateway-server-0:2.5.20260422-2.el8ap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-27606trackedCVSS 9.1Red Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform-26/gateway-rhel9@sha256:1a71e725e9407a4461970dd03b5b0d57caca62765b7342ae1c133fc1ab61400e_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Advanced Cluster Management for Kubernetes 2.15registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:08670904b912776ccbe1b62d7e9e0bbbf376e54c33b34763f2b78f88e395ad5d_amd64Patch ↗Advisory ↗
Red HatCVE-2026-35030trackedCVSS 9.1Red Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform-26/lightspeed-chatbot-rhel9@sha256:1a107e35bf15b706ec620d9140850c29a799ed9497f46f3c1c88dd0eb589ae61_arm64Patch ↗Advisory ↗
AndroidCVE-2026-0073trackedCritical (Android rating)platform/packages/modules/adbNot reportedPatch ↗Advisory ↗
Red HatCVE-2026-34078CVSS 9.0Red Hat Enterprise Linux AppStream (v. 9)flatpak-0:1.12.9-4.el9_8.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-34078CVSS 9.0Red Hat Enterprise Linux AppStream (v. 8)flatpak-0:1.12.9-4.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-34078CVSS 9.0Red Hat Enterprise Linux AppStream (v. 10)flatpak-0:1.16.0-9.el10_2.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-41607CVSS 9.1Multicluster Global Hub 1.5.8registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:8c03495da4214e70589e238a60815c265223952470da6d80034e2f83de5c3c8e_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-7598CVSS 9.1Red Hat Hardened Imagesrust-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-41607CVSS 9.1Red Hat OpenShift distributed tracing 3.9.3registry.redhat.io/rhosdt/tempo-jaeger-query-rhel9@sha256:bea6c0fb2bead67356a76060901018b90c2cda12e5ef0ffca8993e16b761ab41_arm64Patch ↗Advisory ↗
Red HatCVE-2025-61731trackedCVSS 8.6Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:313c0e44208e7fc7d4039f2f22cd01135db0cd3337a258034b774fd7820d8a98_s390xPatch ↗Advisory ↗
Red HatCVE-2026-1526trackedCVSS 7.5Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel9@sha256:1a687d78104fa92356a6af1ef4b5564d8bfd8fa9bc1b02b7ccbdc598be190654_s390xPatch ↗Advisory ↗
Red HatCVE-2026-1528trackedCVSS 7.5Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel9@sha256:1a687d78104fa92356a6af1ef4b5564d8bfd8fa9bc1b02b7ccbdc598be190654_s390xPatch ↗Advisory ↗
Red HatCVE-2026-2229trackedCVSS 7.5Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel9@sha256:1a687d78104fa92356a6af1ef4b5564d8bfd8fa9bc1b02b7ccbdc598be190654_s390xPatch ↗Advisory ↗
Red HatCVE-2026-24049trackedCVSS 7.1Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-ansible-rhel9-operator@sha256:12e5769722f41cfff3ec88000d157eafee309fe3e7262beb93ee1a26eca26740_s390xPatch ↗Advisory ↗
Red HatCVE-2026-25679trackedCVSS 7.5Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:313c0e44208e7fc7d4039f2f22cd01135db0cd3337a258034b774fd7820d8a98_s390xPatch ↗Advisory ↗
Red HatCVE-2026-29063trackedCVSS 8.8Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-monitoring-plugin-rhel9@sha256:67d9273bfa159a5c4911e356c06d992ad3ed91f7b090bacfcb198133f234b0d6_s390xPatch ↗Advisory ↗
Red HatCVE-2026-29063trackedCVSS 8.8Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-console-plugin-rhel9@sha256:1a687d78104fa92356a6af1ef4b5564d8bfd8fa9bc1b02b7ccbdc598be190654_s390xPatch ↗Advisory ↗
SuseCVE-2026-33845trackedCVSS 8.2Open Enterprise Server 25.4gnutls-0:3.8.3-150600.4.20.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-33846trackedCVSS 7.5Open Enterprise Server 25.4gnutls-0:3.8.3-150600.4.20.1.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-34986trackedCVSS 7.5Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-pipelines-as-code-controller-rhel9@sha256:0b165040657b16770b52a0cde7be46db0d6410e6d502b11e7b6053f9ad441c49_amd64Patch ↗Advisory ↗
Red HatCVE-2026-34986trackedCVSS 7.5Red Hat OpenShift Pipelines 1.2registry.redhat.io/openshift-pipelines/pipelines-operator-bundle@sha256:f4100f181620f5424e66633dbdd3c7402c8db75f93c54fe092ff2301d8dd0015_amd64Patch ↗Advisory ↗
Red HatCVE-2026-35535trackedCVSS 7.4Red Hat OpenShift Container Platform 4.16rhcos-aarch64-416.94.202605200242-0Patch ↗Advisory ↗
SuseCVE-2026-42009trackedCVSS 7.5Open Enterprise Server 25.4gnutls-0:3.8.3-150600.4.20.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-42010trackedCVSS 7.1Open Enterprise Server 25.4gnutls-0:3.8.3-150600.4.20.1.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-43503trackedCVSS 7.0Red Hat OpenShift Container Platform 4.16rhcos-aarch64-416.94.202605200242-0Patch ↗Advisory ↗
Red HatCVE-2026-46300trackedCVSS 7.8Red Hat OpenShift Container Platform 4.16rhcos-aarch64-416.94.202605200242-0Patch ↗Advisory ↗
SuseCVE-2026-48863trackedCVSS 7.5openSUSE Tumbleweedlibsolv-demo-0:0.7.38-1.1.aarch64no patch linkAdvisory ↗
Red HatCVE-2025-14813trackedCVSS 7.5Red Hat OpenShift Dev Spaces 3.28registry.redhat.io/devspaces/openvsx-rhel9@sha256:341c8f0f91bd41d4bded00443cd7ab2ddab4972a5ee1ddff4dcbfcdd5c2764f4_arm64Patch ↗Advisory ↗
Red HatCVE-2025-39981trackedCVSS 7.3Red Hat Enterprise Linux BaseOS (v. 8)bpftool-0:4.18.0-553.126.1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-39981trackedCVSS 7.3Red Hat Enterprise Linux NFV (v. 8)kernel-rt-0:4.18.0-553.126.1.rt7.467.el8_10.srcPatch ↗Advisory ↗
Red HatCVE-2025-68183trackedCVSS 7.1Red Hat Enterprise Linux AppStream (v. 9)kernel-64k-debug-debuginfo-0:5.14.0-687.12.1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-68183trackedCVSS 7.1Red Hat Enterprise Linux AppStream (v. 10)kernel-64k-debug-debuginfo-0:6.12.0-211.18.1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-68183trackedCVSS 7.1Red Hat Enterprise Linux BaseOS (v. 8)bpftool-0:4.18.0-553.126.1.el8_10.aarch64Patch ↗Advisory ↗

Glossary