CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Vulnerabilities

May 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 3 vulnerabilities with exploitation detected in the wild this month. This defender-focused view covers 1,835 vulnerabilities across 4,964 returned patch records from 4 vendors. Filter the complete month, or browse the static page trail without JavaScript.

4,964all patch recordsClear filters154criticalShow these records3Microsoft exploitation detectedShow these records4Microsoft in the Known Exploited Vulnerabilities catalogShow these records1,060tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

My Stack only keeps records whose vendor you have pinned. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 22 of 25 · records 4,201 to 4,400 of 4,964

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-39826 ↗azl3 golang 1.25.9-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableEscaper bypass leads to XSS in html/template
CVE-2026-39825 ↗azl3 golang 1.25.9-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil
CVE-2026-39823 ↗azl3 golang 1.25.9-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBypass of meta content URL escaping causes XSS in html/template
CVE-2026-39819 ↗azl3 golang 1.25.9-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableInvoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
CVE-2026-39817 ↗azl3 golang 1.25.9-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableInvoking "go tool pack" does not sanitize output paths in cmd/go
CVE-2026-44656 ↗azl3 vim 9.2.0392-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVim: OS Command Injection via 'path' completion
CVE-2026-45130 ↗azl3 vim 9.2.0392-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVim: Heap Buffer Overflow in spell file loading
CVE-2026-6666 ↗azl3 pgbouncer 1.25.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePgBouncer crash in kill_pool_logins_server_error
CVE-2026-6667 ↗azl3 pgbouncer 1.25.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePgBouncer missing authorization check in KILL_CLIENT admin command
CVE-2026-33846 ↗azl3 gnutls 3.8.3-11 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableGnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly
CVE-2026-37459 ↗azl3 frr 10.5.0-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableAn integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
CVE-2026-37458 ↗azl3 frr 10.5.0-3 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableMissing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.
CVE-2026-43308 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref()
CVE-2026-43311 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesoc/tegra: pmc: Fix unsafe generic_handle_irq() call
CVE-2026-43292 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm/vmalloc: prevent RCU stalls in kasan_release_vmalloc_node
CVE-2026-43294 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels
CVE-2026-43310 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemedia: verisilicon: Avoid G2 bus error while decoding H.264 and HEVC
CVE-2026-43299 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure()
CVE-2026-43305 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Fix mismatched unlock for DMUB HW lock in HWSS fast path
CVE-2026-43456 ↗azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebonding: fix type confusion in bond_setup_by_slave()
CVE-2026-43344 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableperf/x86/intel/uncore: Fix die ID init and look up bugs
CVE-2026-43303 ↗azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm/page_alloc: clear page->private in free_pages_prepare()
CVE-2026-43319 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablespi: spidev: fix lock inversion between spi_lock and buf_lock
CVE-2026-43306 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: crypto: Use the correct destructor kfunc type
CVE-2026-43331 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablex86/kexec: Disable KCOV instrumentation after load_segments()
CVE-2026-43300 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/panel: Fix a possible null-pointer dereference in jdi_panel_dsi_remove()
CVE-2026-43352 ↗azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablei3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue
CVE-2025-71299 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablespi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing
CVE-2026-43416 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepowerpc, perf: Check that current->mm is alive before getting user callchain
CVE-2026-43309 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemd raid: fix hang when stopping arrays with metadata through dm-raid
CVE-2026-43338 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: reserve enough transaction items for qgroup ioctls
CVE-2026-23631 ↗azl3 valkey 8.0.7-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableredis-server Lua use-after-free may allow remote code execution
CVE-2026-33857 ↗azl3 httpd 2.4.66-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableApache HTTP Server: Off-by-one OOB reads in AJP getter functions
CVE-2026-29168 ↗azl3 httpd 2.4.66-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableApache HTTP Server: mod_md unrestricted OCSP response
CVE-2026-29169 ↗azl3 httpd 2.4.66-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableApache HTTP Server: mod_dav_lock indirect lock crash
CVE-2026-33007 ↗azl3 httpd 2.4.66-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableApache HTTP Server: mod_authn_socache crash
CVE-2026-33006 ↗azl3 httpd 2.4.66-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableApache HTTP Server: mod_auth_digest timing attack
CVE-2026-24072 ↗azl3 httpd 2.4.66-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableApache HTTP Server: mod_rewrite elevation of privileges via ap_expr
CVE-2026-34032 ↗azl3 httpd 2.4.66-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableApache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string)
CVE-2026-34059 ↗azl3 httpd 2.4.66-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableApache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data()
CVE-2026-33523 ↗azl3 httpd 2.4.66-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableApache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line
CVE-2026-43868 ↗cbl2 ceph 16.2.10-11 on CBL Mariner 2.0ModerateOut-of-bandNot availableMicrosoft rating unavailableApache Thrift: Rust implementation vulnerable to CVE-2020-13949 pattern
CVE-2026-43199 ↗azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/mlx5e: Fix "scheduling while atomic" in IPsec MAC address query
CVE-2026-43101 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data()
CVE-2026-43119 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: hci_sync: annotate data-races around hdev->req_status
CVE-2026-43216 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: Drop the lock in skb_may_tx_timestamp()
CVE-2025-71272 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemost: core: fix resource leak in most_register_interface error paths
CVE-2026-43195 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: validate user queue size constraints
CVE-2026-43088 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: af_key: zero aligned sockaddr tail in PF_KEY exports
CVE-2026-43165 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablehwmon: (nct7363) Fix a resource leak in nct7363_present_pwm_fanin
CVE-2026-43201 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableAPEI/GHES: ARM processor Error: don't go past allocated memory
CVE-2026-43237 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: Refactor amdgpu_gem_va_ioctl for Handling Last Fence Update and Timeline Management v4
CVE-2026-43250 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableusb: chipidea: udc: fix DMA and SG cleanup in _ep_nuke()
CVE-2025-71294 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: fix NULL pointer issue buffer funcs
CVE-2026-43243 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Add signal type check for dcn401 get_phyd32clk_src
CVE-2026-43107 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablexfrm: account XFRMA_IF_ID in aevent size calculation
CVE-2025-71289 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefs/ntfs3: handle attr_set_size() errors when truncating files
CVE-2026-43191 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Adjust PHY FSM transition to TX_EN-to-PLL_ON for TMDS on DCN35
CVE-2026-43244 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablekcm: fix zero-frag skb in frag_list on partial sendmsg error
CVE-2026-43274 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemailbox: mchp-ipc-sbi: fix out-of-bounds access in mchp_ipc_get_cluster_aggr_irq()
CVE-2026-43116 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: ctnetlink: ensure safe access to master conntrack
CVE-2026-43129 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableima: verify the previous kernel's IMA buffer lies in addressable RAM
CVE-2026-43153 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablexfs: remove xfs_attr_leaf_hasname
CVE-2026-43109 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablex86: shadow stacks: proper error handling for mmap lock
CVE-2026-43118 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: fix zero size inode with non-zero size after log replay
CVE-2025-71273 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()
CVE-2025-71285 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: qrtr: Drop the MHI auto_queue feature for IPCR DL channels
CVE-2026-43172 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: iwlwifi: fix 22000 series SMEM parsing
CVE-2025-71293 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu/ras: Move ras data alloc before bad page check
CVE-2026-43234 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableteam: avoid NETDEV_CHANGEMTU event when unregistering slave
CVE-2026-43115 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesrcu: Use irq_work to start GP in tiny SRCU
CVE-2026-43137 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableASoC: SOF: Intel: hda: Fix NULL pointer dereference
CVE-2025-71290 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemisc: ti_fpc202: fix a potential memory leak in probe function
CVE-2026-43245 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablentfs: ->d_compare() must not block
CVE-2026-43161 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableiommu/vt-d: Skip dev-iotlb flush for inaccessible PCIe device without scalable mode
CVE-2026-43127 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablentfs3: fix circular locking dependency in run_unpack_ex
CVE-2026-43126 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALSA: mixer: oss: Add card disconnect checkpoints
CVE-2026-43131 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/pm: Fix null pointer dereference issue
CVE-2026-43204 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableASoC: qcom: q6asm: drop DSP responses for closed data streams
CVE-2026-43248 ↗azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevhost: move vdpa group bound check to vhost_vdpa
CVE-2026-42154 ↗azl3 telegraf 1.31.0-19 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePrometheus: remote read endpoint allows denial of service via crafted snappy payload
CVE-2026-42151 ↗azl3 telegraf 1.31.0-19 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePrometheus Azure AD remote write OAuth client secret exposed via config API
CVE-2026-37457 ↗azl3 frr 10.5.0-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableAn off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component.

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-31884CVSS 6.5Red Hat Enterprise Linux AppStream (v. 8)freerdp-2:2.11.7-9.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-31885CVSS 6.5Red Hat Enterprise Linux AppStream (v. 10)freerdp-2:3.10.3-5.el10_1.8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-31885CVSS 6.5Red Hat Enterprise Linux AppStream (v. 8)freerdp-2:2.11.7-9.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9Red Hat Enterprise Linux AppStream EUS (v.9.6)go-toolset-0:1.25.9-1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9Red Hat Enterprise Linux AppStream EUS (v. 10.0)go-toolset-0:1.25.9-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9Red Hat Enterprise Linux Server (v. 7 ELS)host-metering-0:1.4.0-7.el7_9.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33982CVSS 6.6Red Hat Enterprise Linux AppStream (v. 10)freerdp-2:3.10.3-5.el10_1.8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33985CVSS 5.3Red Hat Enterprise Linux AppStream (v. 10)freerdp-2:3.10.3-5.el10_1.8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33985CVSS 5.3Red Hat Enterprise Linux AppStream (v. 8)freerdp-2:2.11.7-9.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-35414CVSS 4.8Red Hat Enterprise Linux AppStream EUS (v.9.6)openssh-askpass-0:8.7p1-45.el9_6.3.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-42308CVSS 6.2Red Hat AI Inference Server 3.3registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:3a2527c5c164fad4d2f0fbda199dcd887e5acaf211fe3cd12dc3aa9f499836c0_arm64Patch ↗Advisory ↗
Red HatCVE-2026-42308CVSS 6.2Red Hat AI Inference Server 3.3registry.redhat.io/rhaiis/vllm-rocm-rhel9@sha256:da9b415acbfa49de5960e3d255a1ba0ffad6d0bf67ec1272b1ff70842e819629_amd64Patch ↗Advisory ↗
Red HatCVE-2026-42308CVSS 6.2Red Hat AI Inference Server 3.3registry.redhat.io/rhaiis/vllm-cuda-rhel9@sha256:3aecb1fcf7c282681d9a83ec51fd2fa2ff078567603942466734f55c8294961c_amd64Patch ↗Advisory ↗
Red HatCVE-2026-42309CVSS 5.1Red Hat AI Inference Server 3.3registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:3a2527c5c164fad4d2f0fbda199dcd887e5acaf211fe3cd12dc3aa9f499836c0_arm64Patch ↗Advisory ↗
Red HatCVE-2026-42309CVSS 5.1Red Hat AI Inference Server 3.3registry.redhat.io/rhaiis/vllm-rocm-rhel9@sha256:da9b415acbfa49de5960e3d255a1ba0ffad6d0bf67ec1272b1ff70842e819629_amd64Patch ↗Advisory ↗
Red HatCVE-2026-42309CVSS 5.1Red Hat AI Inference Server 3.3registry.redhat.io/rhaiis/vllm-cuda-rhel9@sha256:3aecb1fcf7c282681d9a83ec51fd2fa2ff078567603942466734f55c8294961c_amd64Patch ↗Advisory ↗
Red HatCVE-2026-42310CVSS 4.0Red Hat AI Inference Server 3.3registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:3a2527c5c164fad4d2f0fbda199dcd887e5acaf211fe3cd12dc3aa9f499836c0_arm64Patch ↗Advisory ↗
Red HatCVE-2026-42310CVSS 4.0Red Hat AI Inference Server 3.3registry.redhat.io/rhaiis/vllm-rocm-rhel9@sha256:da9b415acbfa49de5960e3d255a1ba0ffad6d0bf67ec1272b1ff70842e819629_amd64Patch ↗Advisory ↗
Red HatCVE-2026-42310CVSS 4.0Red Hat AI Inference Server 3.3registry.redhat.io/rhaiis/vllm-cuda-rhel9@sha256:3aecb1fcf7c282681d9a83ec51fd2fa2ff078567603942466734f55c8294961c_amd64Patch ↗Advisory ↗
Red HatCVE-2026-4271CVSS 5.3Red Hat Enterprise Linux AppStream (v. 10)libsoup3-0:3.6.5-3.el10_1.11.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-5119CVSS 5.9Red Hat Enterprise Linux AppStream (v. 10)libsoup3-0:3.6.5-3.el10_1.11.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6757CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.10.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6759CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.10.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6761CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.10.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6762CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.10.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6763CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.10.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6764CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.10.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6765CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.10.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6766CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.10.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6767CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.10.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6769CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.10.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6770CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.10.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6772CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.10.0-1.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-41889CVSS 5.9Red Hat Hardened Imagesgo-fdo-server-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-45287CVSS 4.0Red Hat Hardened Imagespodman-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-45287CVSS 4.0Red Hat Hardened Imagestrivy-0:0.69.3-1.2.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-53489CVSS 6.5Red Hat Hardened Imagestrivy-0:0.69.3-1.2.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-22695CVSS 6.1Red Hat OpenShift Container Platform 4.12rhcos-x86_64-412.86.202604281506-0Patch ↗Advisory ↗
Red HatCVE-2026-22801CVSS 6.6Red Hat OpenShift Container Platform 4.12rhcos-x86_64-412.86.202604281506-0Patch ↗Advisory ↗
Red HatCVE-2026-28417CVSS 4.4Red Hat OpenShift Container Platform 4.12rhcos-x86_64-412.86.202604281506-0Patch ↗Advisory ↗
Red HatCVE-2026-28421CVSS 5.3Red Hat OpenShift Container Platform 4.12rhcos-x86_64-412.86.202604281506-0Patch ↗Advisory ↗
Red HatCVE-2025-46299CVSS 6.5Red Hat Enterprise Linux AppStream EUS (v.9.4)webkit2gtk3-0:2.52.3-1.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-9714CVSS 6.2Red Hat Enterprise Linux AppStream AUS (v.8.4)libxml2-debuginfo-0:2.9.7-9.el8_4.9.i686Patch ↗Advisory ↗
Red HatCVE-2025-9714CVSS 6.2Red Hat Enterprise Linux AppStream E4S (v.8.8)libxml2-debuginfo-0:2.9.7-16.el8_8.13.i686Patch ↗Advisory ↗
Red HatCVE-2026-20643CVSS 5.4Red Hat Enterprise Linux AppStream EUS (v.9.4)webkit2gtk3-0:2.52.3-1.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-20665CVSS 5.4Red Hat Enterprise Linux AppStream EUS (v.9.4)webkit2gtk3-0:2.52.3-1.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-20676CVSS 4.3Red Hat Enterprise Linux AppStream EUS (v.9.4)webkit2gtk3-0:2.52.3-1.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-20691CVSS 4.3Red Hat Enterprise Linux AppStream EUS (v.9.4)webkit2gtk3-0:2.52.3-1.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-28871CVSS 4.3Red Hat Enterprise Linux AppStream EUS (v.9.4)webkit2gtk3-0:2.52.3-1.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33176CVSS 6.5Red Hat Satellite 6.18 for RHEL 9rubygem-activesupport-0:7.0.8.7-2.el9sat.noarchPatch ↗Advisory ↗
Red HatCVE-2026-33176CVSS 6.5Red Hat Satellite 6.17 for RHEL 9rubygem-activesupport-0:7.0.8.7-2.el9sat.noarchPatch ↗Advisory ↗
Red HatCVE-2026-33176CVSS 6.5Red Hat Satellite 6.16 for RHEL 8rubygem-activesupport-0:6.1.7.8-2.el8sat.noarchPatch ↗Advisory ↗
Red HatCVE-2026-35414CVSS 4.8Red Hat Discovery 2registry.redhat.io/discovery/discovery-server-rhel9@sha256:14ec7040666af93b0f95adca24dd3c95962fcd28623f9acadfae115b38b49d61_arm64Patch ↗Advisory ↗
Red HatCVE-2026-4878CVSS 6.7Red Hat Discovery 2registry.redhat.io/discovery/discovery-server-rhel9@sha256:14ec7040666af93b0f95adca24dd3c95962fcd28623f9acadfae115b38b49d61_arm64Patch ↗Advisory ↗
Red HatCVE-2024-41073CVSS 5.5Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)kernel-rt-0:5.14.0-284.169.1.rt14.454.el9_2.srcPatch ↗Advisory ↗
Red HatCVE-2025-37861CVSS 6.3Red Hat Enterprise Linux AppStream E4S (v.9.0)bpftool-debuginfo-0:5.14.0-70.178.1.el9_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-37861CVSS 6.3Red Hat Enterprise Linux NFV E4S (v.9.0)kernel-rt-0:5.14.0-70.178.1.rt21.250.el9_0.srcPatch ↗Advisory ↗
Red HatCVE-2025-67873CVSS 6.1Red Hat Enterprise Linux AppStream E4S (v.9.0)capstone-0:4.0.2-5.el9_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-0636CVSS 6.5Red Hat AMQ Broker 7.13.5Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-0636CVSS 6.5Red Hat AMQ Broker 7.12.7Not reportedPatch ↗Advisory ↗
CiscoCVE-2026-20168CVSS 6.5Cisco IoT Field Network Director4.1Patch ↗Advisory ↗
CiscoCVE-2026-20169CVSS 6.4Cisco IoT Field Network Director4.1Patch ↗Advisory ↗
CiscoCVE-2026-20172CVSS 4.3Cisco Enterprise Chat and Email11.5Patch ↗Advisory ↗
CiscoCVE-2026-20189CVSS 4.3Cisco Prime Infrastructure3.3Patch ↗Advisory ↗
CiscoCVE-2026-20193CVSS 4.3Cisco Identity Services Engine3.3Patch ↗Advisory ↗
CiscoCVE-2026-20195CVSS 5.3Cisco Identity Services Engine3.3Patch ↗Advisory ↗
CiscoCVE-2026-20219CVSS 5.4Apple macOS39Patch ↗Advisory ↗
Red HatCVE-2026-24072CVSS 5.5Red Hat Hardened Imageshttpd-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33007CVSS 5.3Red Hat Hardened Imageshttpd-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-35469CVSS 6.5Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/ose-powervs-block-csi-driver-rhel9@sha256:206cc46dc1980724be995259d1213eaa729bd933da5c61c161d3d977a53a399e_amd64Patch ↗Advisory ↗
Red HatCVE-2026-4878CVSS 6.7Red Hat OpenShift distributed tracing 3.9.3registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:265d8d864589e9ca6739e5eff46be545dc531aa6aa72378674b3ae9ff48f14ac_s390xPatch ↗Advisory ↗
Red HatCVE-2026-5119CVSS 5.9Red Hat Enterprise Linux AppStream (v. 9)libsoup-0:2.72.0-12.el9_7.6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-5119CVSS 5.9Red Hat Enterprise Linux AppStream (v. 8)libsoup-debuginfo-0:2.62.3-14.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6735CVSS 5.4Red Hat Hardened Imagesphp-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-7258CVSS 5.9Red Hat Hardened Imagesphp-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2024-41073CVSS 5.5Red Hat Enterprise Linux BaseOS (v. 8)bpftool-0:4.18.0-553.123.1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2024-41073CVSS 5.5Red Hat Enterprise Linux NFV (v. 8)kernel-rt-0:4.18.0-553.123.1.rt7.464.el8_10.srcPatch ↗Advisory ↗
Red HatCVE-2024-41073CVSS 5.5Red Hat Enterprise Linux AppStream E4S (v.9.2)bpftool-debuginfo-0:7.0.0-284.169.1.el9_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-10158CVSS 4.3Middleware Containers for OpenShiftrhpam-7/rhpam-businesscentral-monitoring-rhel8@sha256:92df715c896f06f6aa93b631bd62e3a146bad3cd08666cbab955d5cccdad0ea0_amd64Patch ↗Advisory ↗
Red HatCVE-2025-14831CVSS 5.3Middleware Containers for OpenShiftrhpam-7/rhpam-businesscentral-monitoring-rhel8@sha256:92df715c896f06f6aa93b631bd62e3a146bad3cd08666cbab955d5cccdad0ea0_amd64Patch ↗Advisory ↗
Red HatCVE-2025-46299CVSS 6.5Red Hat Enterprise Linux AppStream AUS (v.8.6)webkit2gtk3-0:2.52.3-1.el8_6.i686Patch ↗Advisory ↗
Red HatCVE-2025-9820CVSS 4.0Middleware Containers for OpenShiftrhpam-7/rhpam-businesscentral-monitoring-rhel8@sha256:92df715c896f06f6aa93b631bd62e3a146bad3cd08666cbab955d5cccdad0ea0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-0636CVSS 6.5Red Hat build of Quarkus 3.20.6.SP1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-0636CVSS 6.5Red Hat build of Quarkus 3.27.3.SP1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-0636CVSS 6.5Red Hat Build of Apache Camel 4.14 for Quarkus 3.27Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-20643CVSS 5.4Red Hat Enterprise Linux AppStream AUS (v.8.6)webkit2gtk3-0:2.52.3-1.el8_6.i686Patch ↗Advisory ↗
Red HatCVE-2026-20665CVSS 5.4Red Hat Enterprise Linux AppStream AUS (v.8.6)webkit2gtk3-0:2.52.3-1.el8_6.i686Patch ↗Advisory ↗
Red HatCVE-2026-20676CVSS 4.3Red Hat Enterprise Linux AppStream AUS (v.8.6)webkit2gtk3-0:2.52.3-1.el8_6.i686Patch ↗Advisory ↗
Red HatCVE-2026-20691CVSS 4.3Red Hat Enterprise Linux AppStream AUS (v.8.6)webkit2gtk3-0:2.52.3-1.el8_6.i686Patch ↗Advisory ↗
Red HatCVE-2026-27601CVSS 5.9Red Hat Developer Hub 1.9registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:80453720616cee369e9f79863ef1815a2741afdeb25d3572085d11ad54afa9a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-27904CVSS 6.5Red Hat Developer Hub 1.9registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:80453720616cee369e9f79863ef1815a2741afdeb25d3572085d11ad54afa9a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-28871CVSS 4.3Red Hat Enterprise Linux AppStream AUS (v.8.6)webkit2gtk3-0:2.52.3-1.el8_6.i686Patch ↗Advisory ↗
Red HatCVE-2026-3118CVSS 6.5Red Hat Developer Hub 1.9registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:80453720616cee369e9f79863ef1815a2741afdeb25d3572085d11ad54afa9a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-31958CVSS 5.3Red Hat Enterprise Linux AppStream (v. 10)python-tornado-0:6.5.5-1.el10_1.1.srcPatch ↗Advisory ↗
Red HatCVE-2026-31958CVSS 5.3Red Hat Enterprise Linux AppStream (v. 9)python-tornado-0:6.5.5-1.el9_7.1.srcPatch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9Red Hat Advanced Cluster Security 4.9registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:21abe57c756f824d9daa24bb897878bcde142430d8b780d815e55334e9566023_arm64Patch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9Red Hat Advanced Cluster Security for Kubernetes 4.10registry.redhat.io/advanced-cluster-security/rhacs-main-rhel8@sha256:3ec5eba1d09940a2f89969c5bb1193261d39995fe874959a04c349990f75b67b_amd64Patch ↗Advisory ↗
Red HatCVE-2026-34085CVSS 6.6Red Hat Hardened Imagesfontconfig-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-34757CVSS 4.4Red Hat Hardened Imageslibpng-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-35469CVSS 6.5Red Hat Advanced Cluster Security 4.9registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:3a6108facf8ba76db9ebf5cdc468a6edc5c305b92c25f0013c64b8b9f7a90a30_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-35469CVSS 6.5Red Hat Advanced Cluster Security for Kubernetes 4.10registry.redhat.io/advanced-cluster-security/rhacs-roxctl-rhel8@sha256:0025d85b9d60fb1a760e671bf479791b8f254eac53f08562011e90370b80f323_arm64Patch ↗Advisory ↗
Red HatCVE-2026-35536CVSS 5.4Red Hat Enterprise Linux AppStream (v. 10)python-tornado-0:6.5.5-1.el10_1.1.srcPatch ↗Advisory ↗
Red HatCVE-2026-35536CVSS 5.4Red Hat Enterprise Linux AppStream (v. 9)python-tornado-0:6.5.5-1.el9_7.1.srcPatch ↗Advisory ↗
Red HatCVE-2026-35554CVSS 6.8Red Hat build of Quarkus 3.27.3.SP1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-35554CVSS 6.8Red Hat Build of Apache Camel 4.14 for Quarkus 3.27Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-42498CVSS 6.5Red Hat Hardened Imagestomcat11-0:11.0.22-0.1.hum1@noarchPatch ↗Advisory ↗
Red HatCVE-2026-45149CVSS 6.5Red Hat Hardened Imagesnodejs24-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2025-69228CVSS 6.8Red Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform-26/lightspeed-chatbot-rhel9@sha256:1a107e35bf15b706ec620d9140850c29a799ed9497f46f3c1c88dd0eb589ae61_arm64Patch ↗Advisory ↗
Red HatCVE-2026-0598CVSS 4.2Red Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform-26/lightspeed-rhel9@sha256:23c21f847c7fe2e3651a5d1152e46ac91ddf16bb6c6a367c3b9e437da0503ad7_arm64Patch ↗Advisory ↗
Red HatCVE-2026-1002CVSS 5.3Streams for Apache Kafka 3.2.0Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-26996CVSS 6.5Red Hat Ansible Automation Platform 2.6 for RHEL 9automation-platform-ui-0:2.6.8-1.el9ap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-27980CVSS 5.3Streams for Apache Kafka 3.2.0Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-31812CVSS 5.3Red Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform-26/lightspeed-chatbot-rhel9@sha256:1a107e35bf15b706ec620d9140850c29a799ed9497f46f3c1c88dd0eb589ae61_arm64Patch ↗Advisory ↗
Red HatCVE-2026-34352CVSS 6.3Red Hat Enterprise Linux AppStream (v. 8)tigervnc-0:1.15.0-9.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-35414CVSS 4.8Red Hat Enterprise Linux AppStream (v. 10)openssh-askpass-0:9.9p1-14.el10_1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-35414CVSS 4.8Red Hat Enterprise Linux AppStream (v. 9)openssh-askpass-0:8.7p1-49.el9_7.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-35414CVSS 4.8Red Hat Enterprise Linux AppStream (v. 8)openssh-askpass-0:8.0p1-29.el8_10.aarch64Patch ↗Advisory ↗

Glossary