CYBERSECURITYTRACKER
TRACKING3,612 stories653 vuln stories
Patch Day month

May 2026 vulnerabilities

A server-rendered hunting trail for May 2026: 2,180 returned patch records across 4 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.

2,180all patches
140critical
3exploitation detected
4in CISA KEV
544tracked here
Microsoft 1,128Red Hat 1,032Cisco 19Android 1

Page 10 of 11 · records 1,801–2,000 of 2,180

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-7935 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7935 Inappropriate implementation in Speech
CVE-2026-7936 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-bandChromium: CVE-2026-7936 Object lifecycle issue in V8
CVE-2026-7937 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7937 Insufficient policy enforcement in DevTools
CVE-2026-7938 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7938 Use after free in CSS
CVE-2026-7939 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7939 Inappropriate implementation in SanitizerAPI
CVE-2026-7940 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7940 Use after free in V8
CVE-2026-7942 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7942 Integer overflow in ANGLE
CVE-2026-7943 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7943 Insufficient validation of untrusted input in ANGLE
CVE-2026-7944 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7944 Insufficient validation of untrusted input in Persistent Cache
CVE-2026-7945 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7945 Insufficient validation of untrusted input in COOP
CVE-2026-7946 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7946 Insufficient policy enforcement in WebUI
CVE-2026-7947 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7947 Insufficient validation of untrusted input in Network
CVE-2026-7948 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7948 Race in Chromoting
CVE-2026-7949 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7949 Out of bounds read in Skia
CVE-2026-7950 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7950 Out of bounds read and write in GFX
CVE-2026-7951 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7951 Out of bounds write in WebRTC
CVE-2026-7952 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7952 Insufficient policy enforcement in Extensions
CVE-2026-7953 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7953 Insufficient validation of untrusted input in Omnibox
CVE-2026-7954 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7954 Race in Shared Storage
CVE-2026-7955 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7955 Uninitialized Use in GPU
CVE-2026-7956 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7956 Use after free in Navigation
CVE-2026-7957 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7957 Out of bounds write in Media
CVE-2026-7958 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7958 Inappropriate implementation in ServiceWorker
CVE-2026-7959 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7959 Inappropriate implementation in Navigation
CVE-2026-7960 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7960 Race in Speech
CVE-2026-7961 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7961 Insufficient validation of untrusted input in Permissions
CVE-2026-7962 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7962 Insufficient policy enforcement in DirectSockets
CVE-2026-7963 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7963 Inappropriate implementation in ServiceWorker
CVE-2026-7964 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7964 Insufficient validation of untrusted input in FileSystem
CVE-2026-7965 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7965 Insufficient validation of untrusted input in DevTools
CVE-2026-7966 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7966 Insufficient validation of untrusted input in SiteIsolation
CVE-2026-7967 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7967 Insufficient validation of untrusted input in Navigation
CVE-2026-7968 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7968 Insufficient validation of untrusted input in CORS
CVE-2026-7969 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7969 Integer overflow in Network
CVE-2026-7970 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7970 Use after free in TopChrome
CVE-2026-7971 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7971 Inappropriate implementation in ORB
CVE-2026-7972 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7972 Uninitialized Use in GPU
CVE-2026-7973 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7973 Integer overflow in Dawn
CVE-2026-7974 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7974 Use after free in Blink
CVE-2026-7975 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7975 Use after free in DevTools
CVE-2026-7976 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7976 Use after free in Views
CVE-2026-7977 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7977 Inappropriate implementation in Canvas
CVE-2026-7978 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7978 Inappropriate implementation in Companion
CVE-2026-7979 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7979 Inappropriate implementation in Media
CVE-2026-7980 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7980 Use after free in WebAudio
CVE-2026-7981 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7981 Out of bounds read in Codecs
CVE-2026-7982 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7982 Uninitialized Use in WebCodecs
CVE-2026-7983 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7983 Out of bounds read in Dawn
CVE-2026-7984 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7984 Use after free in ReadingMode
CVE-2026-7985 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7985 Use after free in GPU
CVE-2026-7986 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7986 Insufficient policy enforcement in Autofill
CVE-2026-7987 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7987 Use after free in WebRTC
CVE-2026-7988 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7988 Type Confusion in WebRTC
CVE-2026-7989 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7989 Insufficient data validation in DataTransfer
CVE-2026-7990 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7990 Insufficient validation of untrusted input in Updater
CVE-2026-7991 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7991 Use after free in UI
CVE-2026-7992 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7992 Insufficient validation of untrusted input in UI
CVE-2026-7994 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7994 Inappropriate implementation in Chromoting
CVE-2026-7995 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7995 Out of bounds read in AdFilter
CVE-2026-7996 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7996 Insufficient validation of untrusted input in SSL
CVE-2026-7997 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7997 Insufficient validation of untrusted input in Updater
CVE-2026-7998 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7998 Insufficient validation of untrusted input in Dialog
CVE-2026-7999 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7999 Inappropriate implementation in V8
CVE-2026-8000 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8000 Insufficient validation of untrusted input in ChromeDriver
CVE-2026-8001 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8001 Use after free in Printing
CVE-2026-8002 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8002 Use after free in Audio
CVE-2026-8003 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8003 Insufficient validation of untrusted input in TabGroups
CVE-2026-8004 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8004 Insufficient policy enforcement in DevTools
CVE-2026-8005 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8005 Insufficient validation of untrusted input in Cast
CVE-2026-8006 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8006 Insufficient policy enforcement in DevTools
CVE-2026-8007 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8007 Insufficient validation of untrusted input in Cast
CVE-2026-8008 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8008 Inappropriate implementation in DevTools
CVE-2026-8009 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8009 Inappropriate implementation in Cast
CVE-2026-8010 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8010 Insufficient validation of untrusted input in SiteIsolation
CVE-2026-8011 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8011 Insufficient policy enforcement in Search
CVE-2026-8012 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8012 Inappropriate implementation in MHTML
CVE-2026-8013 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8013 Insufficient validation of untrusted input in FedCM
CVE-2026-8014 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8014 Inappropriate implementation in Preload
CVE-2026-8015 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8015 Inappropriate implementation in Media
CVE-2026-8016 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8016 Use after free in WebRTC
CVE-2026-8017 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8017 Side-channel information leakage in Media
CVE-2026-8018 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8018 Insufficient policy enforcement in DevTools
CVE-2026-8019 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8019 Insufficient policy enforcement in WebApp
CVE-2026-8021 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8021 Script injection in UI
CVE-2026-8022 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8022 Inappropriate implementation in MHTML
CVE-2026-33857 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ModerateOut-of-bandApache HTTP Server: Off-by-one OOB reads in AJP getter functions
CVE-2026-29168 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-bandApache HTTP Server: mod_md unrestricted OCSP response
CVE-2026-29169 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-bandApache HTTP Server: mod_dav_lock indirect lock crash
CVE-2026-33007 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ModerateOut-of-bandApache HTTP Server: mod_authn_socache crash
CVE-2026-33006 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ModerateOut-of-bandApache HTTP Server: mod_auth_digest timing attack
CVE-2026-24072 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-bandApache HTTP Server: mod_rewrite elevation of privileges via ap_expr
CVE-2026-34032 ↗2026-05-07azl3 httpd 2.4.66-1 on Azure Linux 3.0ModerateOut-of-bandApache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)
CVE-2026-34059 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-bandApache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data()
CVE-2026-23918 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-bandApache HTTP Server: http2: double free and possible RCE on early reset
CVE-2026-33523 ↗2026-05-07cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ModerateOut-of-bandApache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line
CVE-2026-43868 ↗2026-05-07cbl2 ceph 16.2.10-11 on CBL Mariner 2.0ModerateOut-of-bandApache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern
CVE-2026-43870 ↗2026-05-07cbl2 ceph 16.2.10-11 on CBL Mariner 2.0ImportantOut-of-bandApache Thrift: Node.js web_server.js multi-vulnerability
CVE-2026-43083 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: ioam6: fix OOB and missing lock
CVE-2026-43199 ↗2026-05-07azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query
CVE-2026-43101 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data()
CVE-2026-43267 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-bandwifi: rtw89: fix potential zero beacon interval in beacon tracking
CVE-2026-43119 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandBluetooth: hci_sync: annotate data-races around hdev->req_status
CVE-2026-43216 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: Drop the lock in skb_may_tx_timestamp()
CVE-2026-43228 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-bandhfs: Replace BUG_ON with error handling for CNID count checks
CVE-2026-43213 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-bandwifi: rtw89: pci: validate sequence number of TX release report
CVE-2025-71272 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandmost: core: fix resource leak in most_register_interface error paths
CVE-2026-43195 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: validate user queue size constraints
CVE-2026-43088 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandnet: af_key: zero aligned sockaddr tail in PF_KEY exports
CVE-2026-43165 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandhwmon: (nct7363) Fix a resource leak in nct7363_present_pwm_fanin
CVE-2026-43219 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-bandnet: cpsw_new: Fix potential unregister of netdev that has not been registered yet
CVE-2026-43201 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandAPEI/GHES: ARM processor Error: don't go past allocated memory
CVE-2026-43237 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4
CVE-2026-43250 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandusb: chipidea: udc: fix DMA and SG cleanup in _ep_nuke()
CVE-2025-71294 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: fix NULL pointer issue buffer funcs
CVE-2026-43243 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Add signal type check for dcn401 get_phyd32clk_src
CVE-2026-43107 ↗2026-05-07azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandxfrm: account XFRMA_IF_ID in aevent size calculation
CVE-2025-71289 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandfs/ntfs3: handle attr_set_size() errors when truncating files
CVE-2026-43258 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-bandalpha: fix user-space corruption during memory compaction
CVE-2026-43191 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Adjust PHY FSM transition to TX_EN-to-PLL_ON for TMDS on DCN35
CVE-2026-43244 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandkcm: fix zero-frag skb in frag_list on partial sendmsg error
CVE-2026-43274 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandmailbox: mchp-ipc-sbi: fix out-of-bounds access in mchp_ipc_get_cluster_aggr_irq()
CVE-2026-43116 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandnetfilter: ctnetlink: ensure safe access to master conntrack
CVE-2026-43129 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandima: verify the previous kernel's IMA buffer lies in addressable RAM
CVE-2026-43153 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandxfs: remove xfs_attr_leaf_hasname
CVE-2026-43109 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandx86: shadow stacks: proper error handling for mmap lock
CVE-2026-43118 ↗2026-05-07azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix zero size inode with non-zero size after log replay
CVE-2025-71273 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandwifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()
CVE-2026-43185 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandksmbd: fix signededness bug in smb_direct_prepare_negotiation()
CVE-2026-43197 ↗2026-05-07azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandnetconsole: avoid OOB reads, msg is not nul-terminated
CVE-2025-71285 ↗2026-05-07azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: qrtr: Drop the MHI auto_queue feature for IPCR DL channels
CVE-2026-43172 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandwifi: iwlwifi: fix 22000 series SMEM parsing
CVE-2025-71293 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu/ras: Move ras data alloc before bad page check
CVE-2026-43234 ↗2026-05-07azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandteam: avoid NETDEV_CHANGEMTU event when unregistering slave
CVE-2026-43115 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandsrcu: Use irq_work to start GP in tiny SRCU
CVE-2026-43137 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandASoC: SOF: Intel: hda: Fix NULL pointer dereference
CVE-2025-71290 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandmisc: ti_fpc202: fix a potential memory leak in probe function
CVE-2026-43245 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandntfs: ->d_compare() must not block
CVE-2026-43198 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandtcp: fix potential race in tcp_v6_syn_recv_sock()
CVE-2026-43161 ↗2026-05-07azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandiommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode
CVE-2026-43127 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandntfs3: fix circular locking dependency in run_unpack_ex
CVE-2026-43126 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandALSA: mixer: oss: Add card disconnect checkpoints
CVE-2026-43131 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amd/pm: Fix null pointer dereference issue
CVE-2026-43204 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandASoC: qcom: q6asm: drop DSP responses for closed data streams
CVE-2026-43176 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-bandwifi: rtw89: pci: validate release report content before using for RTL8922DE
CVE-2026-43248 ↗2026-05-07azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-bandvhost: move vdpa group bound check to vhost_vdpa
CVE-2026-43125 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-banddlm: validate length in dlm_search_rsb_tree
CVE-2026-42154 ↗2026-05-07cbl2 prometheus 2.37.9-7 on CBL Mariner 2.0ImportantOut-of-bandPrometheus: remote read endpoint allows denial of service via crafted snappy payload
CVE-2026-42151 ↗2026-05-07cbl2 prometheus 2.37.9-7 on CBL Mariner 2.0ImportantOut-of-bandPrometheus Azure AD remote write OAuth client secret exposed via config API
CVE-2026-43073 ↗2026-05-07azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandx86-64: rename misleadingly named '__copy_user_nocache()' function
CVE-2026-35579 ↗2026-05-07azl3 coredns 1.11.4-15 on Azure Linux 3.0ImportantOut-of-bandCoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transports
CVE-2026-32934 ↗2026-05-07azl3 coredns 1.11.4-15 on Azure Linux 3.0ImportantOut-of-bandCoreDNS DNS-over-QUIC unbounded goroutine growth leads to denial of service
CVE-2026-32936 ↗2026-05-07azl3 coredns 1.11.4-15 on Azure Linux 3.0ImportantOut-of-bandCoreDNS DoH GET path missing size validation causes CPU and memory amplification
CVE-2026-33489 ↗2026-05-07azl3 coredns 1.11.4-15 on Azure Linux 3.0ImportantOut-of-bandCoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison
CVE-2026-33190 ↗2026-05-07azl3 coredns 1.11.4-15 on Azure Linux 3.0ImportantOut-of-bandCoreDNS TSIG authentication bypass on encrypted DNS transports
CVE-2026-43037 ↗2026-05-06cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-bandip6_tunnel: clear skb2->cb[] in ip4ip6_err()
CVE-2026-43964 ↗2026-05-06azl3 postfix 3.9.0-2 on Azure Linux 3.0LowOut-of-bandPostfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash via an enhanced status code that lacks text after the third number.

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2025-13465CVSS 8.2Red Hat Satellite 6.18registry.redhat.io/satellite/iop-advisor-frontend-rhel9@sha256:1a9489fdc27626a7942f7406beae9994fe94b877010e2c7ff6077db880c7b52a_amd64Patch ↗Advisory ↗
Red HatCVE-2025-13465CVSS 8.2Red Hat Satellite 6.18registry.redhat.io/satellite/iop-host-inventory-frontend-rhel9@sha256:7a9a21eeb4b7d200c14a50ecfde4fa675835ec514f9b120357d787e5430776b2_amd64Patch ↗Advisory ↗
Red HatCVE-2025-61726CVSS 7.5Red Hat Satellite 6.18registry.redhat.io/satellite/iop-vmaas-rhel9@sha256:8bc6388b3b83875d286cb3b5a4bd5f5157a9634350611019770fe44f608e3c34_amd64Patch ↗Advisory ↗
Red HatCVE-2025-62718CVSS 7.0Red Hat Discovery 2registry.redhat.io/discovery/discovery-ui-rhel9@sha256:01916a5cf8a81464cabb2e17ba255fe5006b5c25b25384451f483dd792c9d332_arm64Patch ↗Advisory ↗
Red HatCVE-2025-66418CVSS 7.5Red Hat Satellite 6.18registry.redhat.io/satellite/iop-puptoo-rhel9@sha256:45a0ac91d832d0d67b50b8a5423e1156d824f87f1046cdadefe4f7f09ff3adb5_amd64Patch ↗Advisory ↗
Red HatCVE-2025-66471CVSS 7.5Red Hat Satellite 6.18registry.redhat.io/satellite/iop-puptoo-rhel9@sha256:45a0ac91d832d0d67b50b8a5423e1156d824f87f1046cdadefe4f7f09ff3adb5_amd64Patch ↗Advisory ↗
Red HatCVE-2025-68121CVSS 7.4Red Hat Satellite 6.18registry.redhat.io/satellite/iop-vmaas-rhel9@sha256:8bc6388b3b83875d286cb3b5a4bd5f5157a9634350611019770fe44f608e3c34_amd64Patch ↗Advisory ↗
Red HatCVE-2026-21441CVSS 7.5Red Hat Satellite 6.18registry.redhat.io/satellite/iop-puptoo-rhel9@sha256:45a0ac91d832d0d67b50b8a5423e1156d824f87f1046cdadefe4f7f09ff3adb5_amd64Patch ↗Advisory ↗
Red HatCVE-2026-25679CVSS 7.5Red Hat Satellite 6.18registry.redhat.io/satellite/iop-vmaas-rhel9@sha256:8bc6388b3b83875d286cb3b5a4bd5f5157a9634350611019770fe44f608e3c34_amd64Patch ↗Advisory ↗
Red HatCVE-2026-27135CVSS 7.5Red Hat Discovery 2registry.redhat.io/discovery/discovery-server-rhel9@sha256:14ec7040666af93b0f95adca24dd3c95962fcd28623f9acadfae115b38b49d61_arm64Patch ↗Advisory ↗
Red HatCVE-2026-27137CVSS 7.5Red Hat Satellite 6.18registry.redhat.io/satellite/iop-vmaas-rhel9@sha256:8bc6388b3b83875d286cb3b5a4bd5f5157a9634350611019770fe44f608e3c34_amd64Patch ↗Advisory ↗
Red HatCVE-2026-28390CVSS 7.5Red Hat Discovery 2registry.redhat.io/discovery/discovery-server-rhel9@sha256:14ec7040666af93b0f95adca24dd3c95962fcd28623f9acadfae115b38b49d61_arm64Patch ↗Advisory ↗
Red HatCVE-2026-35385CVSS 7.5Red Hat Discovery 2registry.redhat.io/discovery/discovery-server-rhel9@sha256:14ec7040666af93b0f95adca24dd3c95962fcd28623f9acadfae115b38b49d61_arm64Patch ↗Advisory ↗
Red HatCVE-2026-35386CVSS 3.6Red Hat Discovery 2registry.redhat.io/discovery/discovery-server-rhel9@sha256:14ec7040666af93b0f95adca24dd3c95962fcd28623f9acadfae115b38b49d61_arm64Patch ↗Advisory ↗
Red HatCVE-2026-35387CVSS 3.1Red Hat Discovery 2registry.redhat.io/discovery/discovery-server-rhel9@sha256:14ec7040666af93b0f95adca24dd3c95962fcd28623f9acadfae115b38b49d61_arm64Patch ↗Advisory ↗
Red HatCVE-2026-35388CVSS 2.2Red Hat Discovery 2registry.redhat.io/discovery/discovery-server-rhel9@sha256:14ec7040666af93b0f95adca24dd3c95962fcd28623f9acadfae115b38b49d61_arm64Patch ↗Advisory ↗
Red HatCVE-2026-35414CVSS 4.8Red Hat Discovery 2registry.redhat.io/discovery/discovery-server-rhel9@sha256:14ec7040666af93b0f95adca24dd3c95962fcd28623f9acadfae115b38b49d61_arm64Patch ↗Advisory ↗
Red HatCVE-2026-40175CVSS 9.0Red Hat Discovery 2registry.redhat.io/discovery/discovery-ui-rhel9@sha256:01916a5cf8a81464cabb2e17ba255fe5006b5c25b25384451f483dd792c9d332_arm64Patch ↗Advisory ↗
Red HatCVE-2026-40895CVSS 7.5Red Hat Discovery 2registry.redhat.io/discovery/discovery-ui-rhel9@sha256:01916a5cf8a81464cabb2e17ba255fe5006b5c25b25384451f483dd792c9d332_arm64Patch ↗Advisory ↗
Red HatCVE-2026-42033CVSS 7.4Red Hat Discovery 2registry.redhat.io/discovery/discovery-ui-rhel9@sha256:01916a5cf8a81464cabb2e17ba255fe5006b5c25b25384451f483dd792c9d332_arm64Patch ↗Advisory ↗
Red HatCVE-2026-42035CVSS 7.4Red Hat Discovery 2registry.redhat.io/discovery/discovery-ui-rhel9@sha256:01916a5cf8a81464cabb2e17ba255fe5006b5c25b25384451f483dd792c9d332_arm64Patch ↗Advisory ↗
Red HatCVE-2026-42039CVSS 7.5Red Hat Discovery 2registry.redhat.io/discovery/discovery-ui-rhel9@sha256:01916a5cf8a81464cabb2e17ba255fe5006b5c25b25384451f483dd792c9d332_arm64Patch ↗Advisory ↗
Red HatCVE-2026-42041CVSS 8.2Red Hat Discovery 2registry.redhat.io/discovery/discovery-ui-rhel9@sha256:01916a5cf8a81464cabb2e17ba255fe5006b5c25b25384451f483dd792c9d332_arm64Patch ↗Advisory ↗
Red HatCVE-2026-42043CVSS 7.2Red Hat Discovery 2registry.redhat.io/discovery/discovery-ui-rhel9@sha256:01916a5cf8a81464cabb2e17ba255fe5006b5c25b25384451f483dd792c9d332_arm64Patch ↗Advisory ↗
Red HatCVE-2026-4424CVSS 7.5Red Hat Discovery 2registry.redhat.io/discovery/discovery-server-rhel9@sha256:14ec7040666af93b0f95adca24dd3c95962fcd28623f9acadfae115b38b49d61_arm64Patch ↗Advisory ↗
Red HatCVE-2026-4800CVSS 8.1Red Hat Satellite 6.18registry.redhat.io/satellite/iop-advisor-frontend-rhel9@sha256:1a9489fdc27626a7942f7406beae9994fe94b877010e2c7ff6077db880c7b52a_amd64Patch ↗Advisory ↗
Red HatCVE-2026-4800CVSS 8.1Red Hat Satellite 6.18registry.redhat.io/satellite/iop-host-inventory-frontend-rhel9@sha256:7a9a21eeb4b7d200c14a50ecfde4fa675835ec514f9b120357d787e5430776b2_amd64Patch ↗Advisory ↗
Red HatCVE-2026-4878CVSS 6.7Red Hat Discovery 2registry.redhat.io/discovery/discovery-server-rhel9@sha256:14ec7040666af93b0f95adca24dd3c95962fcd28623f9acadfae115b38b49d61_arm64Patch ↗Advisory ↗
Red HatCVE-2026-5121CVSS 7.5Red Hat Discovery 2registry.redhat.io/discovery/discovery-ui-rhel9@sha256:01916a5cf8a81464cabb2e17ba255fe5006b5c25b25384451f483dd792c9d332_arm64Patch ↗Advisory ↗
Red HatCVE-2025-61731CVSS 8.6Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:1603e1a021f3c0e49013aa2b424b2177d0a611651b00c6ad928eec414807998d_arm64Patch ↗Advisory ↗
Red HatCVE-2025-61731CVSS 8.6Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/ose-tests-rhel9@sha256:07a4e4ee921cba5f48cbeb44e011b7029deebd7db0c06778d4c903a771ddcee3_arm64Patch ↗Advisory ↗
Red HatCVE-2025-65637CVSS 7.5Red Hat Enterprise Linux AppStream E4S (v.9.2)skopeo-2:1.11.4-0.1.el9_2.5.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-23479CVSS 7.5Red Hat Hardened Imagesvalkey-main@aarch64Patch ↗Advisory ↗