Patch Day month
May 2026 vulnerabilities
A server-rendered hunting trail for May 2026: 2,180 returned patch records across 4 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.
2,180all patches
140critical
3exploitation detected
4in CISA KEV
544tracked here
Microsoft 1,128Red Hat 1,032Cisco 19Android 1
Page 7 of 11 · records 1,201–1,400 of 2,180
Microsoft Security Response Center
CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-8328 ↗2026-05-17azl3 python3 3.12.9-11 on Azure Linux 3.0ModerateOut-of-band—FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
CVE-2026-8368 ↗2026-05-17azl3 perl-libwww-perl 6.72-1 on Azure Linux 3.0ModerateOut-of-band—LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects
CVE-2026-44283 ↗2026-05-17azl3 etcd 3.5.28-1 on Azure Linux 3.0ModerateOut-of-band—etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks
CVE-2026-46483 ↗2026-05-17azl3 vim 9.2.0392-1 on Azure Linux 3.0LowOut-of-band—Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag
CVE-2026-43490 ↗2026-05-16azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ImportantOut-of-band—ksmbd: validate inherited ACE SID length
CVE-2026-46333 ↗2026-05-16azl3 kernel-hwe 6.12.0.0-1 on Azure Linux 3.0ModerateOut-of-band—ptrace: slightly saner 'get_dumpable()' logic
CVE-2026-44662 ↗2026-05-16azl3 clamav 1.5.2-2 on Azure Linux 3.0ModerateOut-of-band—rust-openssl: Heap buffer overflow when encrypting with AES key-wrap-with-padding
CVE-2026-44431 ↗2026-05-16azl3 python-urllib3 2.0.7-4 on Azure Linux 3.0ImportantOut-of-band—urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
CVE-2026-42946 ↗2026-05-16azl3 nginx 1.28.3-1 on Azure Linux 3.0ImportantOut-of-band—NGINX ngx_http_scgi_module and ngx_http_uwsgi_module vulnerability
CVE-2026-42945 ↗2026-05-16azl3 nginx 1.28.3-1 on Azure Linux 3.0CriticalOut-of-band61%VulnCheck1 mentionsNGINX ngx_http_rewrite_module vulnerability
CVE-2026-42934 ↗2026-05-16azl3 nginx 1.28.3-1 on Azure Linux 3.0ModerateOut-of-band—NGINX ngx_http_charset_module vulnerability
CVE-2026-40701 ↗2026-05-16azl3 nginx 1.28.3-1 on Azure Linux 3.0ModerateOut-of-band—NGINX ngx_http_ssl_module vulnerability
CVE-2026-40460 ↗2026-05-16azl3 nginx 1.28.3-1 on Azure Linux 3.0ModerateOut-of-band—NGINX ngx_quic_module vulnerability
CVE-2026-6479 ↗2026-05-16azl3 postgresql 16.12-1 on Azure Linux 3.0ImportantOut-of-band—PostgreSQL SSL/GSS init causes denial of service, via uncontrolled recursion
CVE-2026-6477 ↗2026-05-16azl3 rust 1.75.0-28 on Azure Linux 3.0ImportantOut-of-band—PostgreSQL libpq lo_* functions let server superuser overwrite client stack memory
CVE-2026-6637 ↗2026-05-16azl3 postgresql 16.12-1 on Azure Linux 3.0ImportantOut-of-band—PostgreSQL refint allows stack buffer overflow and SQL injection
CVE-2026-6472 ↗2026-05-16azl3 postgresql 16.12-1 on Azure Linux 3.0ModerateOut-of-band—PostgreSQL CREATE TYPE does not check multirange schema CREATE privilege
CVE-2026-6474 ↗2026-05-16azl3 postgresql 16.12-1 on Azure Linux 3.0ModerateOut-of-band—PostgreSQL timeofday() can disclose portions of server memory
CVE-2026-6475 ↗2026-05-16azl3 postgresql 16.12-1 on Azure Linux 3.0ImportantOut-of-band—PostgreSQL pg_basebackup and pg_rewind can overwrite unrelated files of origin superuser choice
CVE-2026-6638 ↗2026-05-16azl3 postgresql 16.12-1 on Azure Linux 3.0LowOut-of-band—PostgreSQL REFRESH PUBLICATION allows SQL injection via table name
CVE-2026-6473 ↗2026-05-16azl3 rust 1.75.0-28 on Azure Linux 3.0ImportantOut-of-band—PostgreSQL server undersizes allocations, via integer wraparound
CVE-2026-6478 ↗2026-05-16azl3 postgresql 16.12-1 on Azure Linux 3.0ModerateOut-of-band—PostgreSQL discloses MD5-hashed passwords via covert timing channel
CVE-2026-44673 ↗2026-05-16azl3 libyang 2.1.148-1 on Azure Linux 3.0ImportantOut-of-band—libyang: lyb_read_string() integer overflow → heap buffer overflow
CVE-2026-8587 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8587 Use after free in Extensions
CVE-2026-8586 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8586 Inappropriate implementation in Chromoting
CVE-2026-8585 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8585 Inappropriate implementation in Media
CVE-2026-8584 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8584 Inappropriate implementation in Views
CVE-2026-8583 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8583 Insufficient policy enforcement in WebXR
CVE-2026-8582 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8582 Object lifecycle issue in Dawn
CVE-2026-8581 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8581 Use after free in GPU
CVE-2026-8580 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8580 Use after free in Mojo
CVE-2026-8579 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8579 Insufficient validation of untrusted input in Skia
CVE-2026-8578 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8578 Out of bounds read in GPU
CVE-2026-8577 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8577 Integer overflow in Fonts
CVE-2026-8576 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8576 Inappropriate implementation in CORS
CVE-2026-8575 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8575 Use after free in UI
CVE-2026-8573 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8573 Integer overflow in Codecs
CVE-2026-8574 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8574 Use after free in Core
CVE-2026-8572 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8572 Insufficient policy enforcement in Network
CVE-2026-8571 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8571 Insufficient policy enforcement in GPU
CVE-2026-8570 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8570 Type Confusion in V8
CVE-2026-8569 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8569 Out of bounds write in Codecs
CVE-2026-8568 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band—Chromium: CVE-2026-8568 Insufficient policy enforcement in AI
CVE-2026-8566 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8566 Insufficient policy enforcement in Payments
CVE-2026-8567 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8567 Integer overflow in ANGLE
CVE-2026-8565 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8565 Inappropriate implementation in Downloads
CVE-2026-8564 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8564 Incorrect security UI in Downloads
CVE-2026-8563 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8563 Insufficient policy enforcement in IFrame Sandbox
CVE-2026-8562 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8562 Side-channel information leakage in Navigation
CVE-2026-8561 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8561 Incorrect security UI in Fullscreen
CVE-2026-8560 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8560 Heap buffer overflow in SwiftShader
CVE-2026-8559 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8559 Integer overflow in Internationalization
CVE-2026-8558 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8558 Out of bounds write in Fonts
CVE-2026-8557 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8557 Use after free in Accessibility
CVE-2026-8555 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8555 Use after free in GTK
CVE-2026-8556 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8556 Inappropriate implementation in ANGLE
CVE-2026-8554 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8554 Type Confusion in ANGLE
CVE-2026-8553 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8553 Use after free in GPU
CVE-2026-8552 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8552 Heap buffer overflow in GPU
CVE-2026-8551 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8551 Use after free in Downloads
CVE-2026-8550 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8550 Use after free in Google Lens
CVE-2026-8549 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8549 Use after free in Media
CVE-2026-8548 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8548 Out of bounds write in Media
CVE-2026-8547 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8547 Insufficient policy enforcement in Passwords
CVE-2026-8546 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8546 Out of bounds read in GPU
CVE-2026-8545 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8545 Object corruption in Compositing
CVE-2026-8544 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8544 Use after free in Media
CVE-2026-8543 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8543 Out of bounds read in FileSystem
CVE-2026-8542 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8542 Use after free in Core
CVE-2026-8541 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8541 Out of bounds read in UI
CVE-2026-8540 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8540 Type Confusion in V8
CVE-2026-8539 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8539 Script injection in SanitizerAPI
CVE-2026-8538 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8538 Insufficient validation of untrusted input in GPU
CVE-2026-8537 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8537 Insufficient policy enforcement in ViewTransitions
CVE-2026-8536 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8536 Insufficient validation of untrusted input in ReadingMode
CVE-2026-8535 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8535 Out of bounds read in Media
CVE-2026-8534 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8534 Integer overflow in GPU
CVE-2026-8533 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8533 Use after free in Accessibility
CVE-2026-8532 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8532 Integer overflow in XML
CVE-2026-8531 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8531 Heap buffer overflow in WebML
CVE-2026-8530 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8530 Use after free in Network
CVE-2026-8529 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8529 Heap buffer overflow in Codecs
CVE-2026-8528 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8528 Insufficient validation of untrusted input in SiteIsolation
CVE-2026-8527 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8527 Insufficient validation of untrusted input in Downloads
CVE-2026-8526 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8526 Out of bounds write in WebRTC
CVE-2026-8525 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8525 Heap buffer overflow in ANGLE
CVE-2026-8524 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8524 Out of bounds write in WebAudio
CVE-2026-8523 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8523 Use after free in Mojo
CVE-2026-8519 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8519 Integer overflow in ANGLE
CVE-2026-8518 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8518 Use after free in Blink
CVE-2026-8517 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8517 Object lifecycle issue in WebShare
CVE-2026-8516 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8516 Insufficient validation of untrusted input in DataTransfer
CVE-2026-8514 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8514 Use after free in Aura
CVE-2026-8515 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8515 Use after free in HID
CVE-2026-8513 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8513 Use after free in Input
CVE-2026-8512 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8512 Use after free in FileSystem
CVE-2026-8511 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8511 Use after free in UI
CVE-2026-8510 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8510 Integer overflow in Skia
CVE-2026-8509 ↗2026-05-15Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8509 Heap buffer overflow in WebML
CVE-2026-45492 ↗2026-05-15Microsoft Edge (Chromium-based)ModerateOut-of-band0%More likelyMicrosoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2026-45494 ↗2026-05-15Microsoft Edge (Chromium-based)ModerateOut-of-band0%More likelyMicrosoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-45495 ↗2026-05-15Microsoft Edge (Chromium-based)ImportantOut-of-band1%More likelyMicrosoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2026-43968 ↗2026-05-15azl3 rabbitmq-server 3.13.7-3 on Azure Linux 3.0LowOut-of-band—CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1
CVE-2026-7790 ↗2026-05-15azl3 rabbitmq-server 3.13.7-3 on Azure Linux 3.0ModerateOut-of-band—Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS
CVE-2026-43969 ↗2026-05-15azl3 rabbitmq-server 3.13.7-3 on Azure Linux 3.0LowOut-of-band—Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
CVE-2026-7210 ↗2026-05-15azl3 python3 3.12.9-10 on Azure Linux 3.0ModerateOut-of-band—The expat and elementtree parsers use insufficient entropy for XML hash-flooding protection
CVE-2026-34956 ↗2026-05-15azl3 openvswitch 3.3.0-3 on Azure Linux 3.0ModerateOut-of-band—Openvswitch: open vswitch: denial of service via malformed ftp epasv command
CVE-2026-42011 ↗2026-05-15azl3 gnutls 3.8.3-8 on Azure Linux 3.0ModerateOut-of-band—Gnutls: gnutls: security bypass due to incorrect name constraint handling
CVE-2026-42010 ↗2026-05-15azl3 gnutls 3.8.3-8 on Azure Linux 3.0ModerateOut-of-band—Gnutls: gnutls: authentication bypass via nul character in username
CVE-2026-8295 ↗2026-05-15azl3 simdjson 3.11.6-2 on Azure Linux 3.0LowOut-of-band—Integer overflow in simdjson
CVE-2026-42304 ↗2026-05-15azl3 python-twisted 22.10.0-4 on Azure Linux 3.0ImportantOut-of-band—Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
CVE-2026-41615 ↗2026-05-14Microsoft Authenticator for AndroidCriticalOut-of-band1%Microsoft Authenticator Information Disclosure Vulnerability
CVE-2026-42897 ↗2026-05-14Microsoft Exchange Server 2016 Cumulative Update 23CriticalOut-of-band70%Exploitation detectedCISA KEVVulnCheckENISAKB5094139KB50941402 mentionsMicrosoft Exchange Server Spoofing Vulnerability
CVE-2026-5773 ↗2026-05-14azl3 curl 8.11.1-6 on Azure Linux 3.0ModerateOut-of-band—wrong reuse of SMB connection
CVE-2026-7168 ↗2026-05-14azl3 curl 8.11.1-6 on Azure Linux 3.0ModerateOut-of-band—cross-proxy Digest auth state leak
CVE-2026-6253 ↗2026-05-14azl3 curl 8.11.1-6 on Azure Linux 3.0ModerateOut-of-band—proxy credentials leak over redirect-to proxy
CVE-2026-5545 ↗2026-05-14azl3 curl 8.11.1-6 on Azure Linux 3.0ModerateOut-of-band—wrong reuse of HTTP Negotiate connection
CVE-2026-6429 ↗2026-05-14azl3 curl 8.11.1-6 on Azure Linux 3.0ModerateOut-of-band—netrc credential leak with reused proxy connection
CVE-2026-4873 ↗2026-05-14azl3 curl 8.11.1-6 on Azure Linux 3.0ModerateOut-of-band—connection reuse ignores TLS requirement
CVE-2026-6276 ↗2026-05-14azl3 curl 8.11.1-6 on Azure Linux 3.0ModerateOut-of-band—stale custom cookie host causes cookie leak
CVE-2026-44307 ↗2026-05-14azl3 python-mako 1.2.4-3 on Azure Linux 3.0ImportantOut-of-band—Mako: Path traversal via backslash URI on Windows in TemplateLookup
CVE-2026-43220 ↗2026-05-14azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-band—iommu/amd: serialize sequence allocation under concurrent TLB invalidations
CVE-2026-44777 ↗2026-05-14azl3 jq 1.7.1-5 on Azure Linux 3.0ModerateOut-of-band—jq: stack overflow in module loading on mutual `include`
CVE-2026-6210 ↗2026-05-13azl3 qtsvg 6.6.1-3 on Azure Linux 3.0ImportantOut-of-band—Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application crash
CVE-2026-8177 ↗2026-05-13azl3 perl-XML-LibXML 2.0209-2 on Azure Linux 3.0ModerateOut-of-band—XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences
CVE-2026-43249 ↗2026-05-13azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ImportantOut-of-band—9p/xen: protect xen_9pfs_front_free against concurrent calls
CVE-2026-31767 ↗2026-05-13azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-band—drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode
CVE-2026-41256 ↗2026-05-13azl3 jq 1.7.1-5 on Azure Linux 3.0ModerateOut-of-band—jq: Embedded NUL truncates top-level jq programs loaded with -f
CVE-2026-40612 ↗2026-05-13azl3 jq 1.7.1-5 on Azure Linux 3.0ModerateOut-of-band—jq: Stack overflow via unbounded recursion in jv_contains
CVE-2026-43895 ↗2026-05-13azl3 jq 1.7.1-5 on Azure Linux 3.0ModerateOut-of-band—jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves sensitive fields in published artifacts
CVE-2026-43896 ↗2026-05-13azl3 jq 1.7.1-5 on Azure Linux 3.0ModerateOut-of-band—jq: Stack Overflow in Recursive Object Merge
CVE-2026-43894 ↗2026-05-13azl3 jq 1.7.1-5 on Azure Linux 3.0ModerateOut-of-band—jq: Wild stack write via signed-integer overflow in decNumber D2U() macro
CVE-2026-41257 ↗2026-05-13azl3 jq 1.7.1-5 on Azure Linux 3.0ModerateOut-of-band—jq: Signed-int overflow in `stack_reallocate` (jq VM stack)
Cross-vendor patches
VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-3505CVSS 7.5Red Hat JBoss EAP 8.1 for RHEL 9eap8-bouncycastle-0:1.84.0-1.redhat_00001.1.el9eap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-5588CVSS 7.5Red Hat JBoss EAP 8.1 for RHEL 8eap8-bouncycastle-0:1.84.0-1.redhat_00001.1.el8eap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-5588CVSS 7.5Red Hat JBoss EAP 8.1 for RHEL 9eap8-activemq-artemis-0:2.40.0-6.redhat_00012.1.el9eap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-5598CVSS 7.5Red Hat JBoss EAP 8.1 for RHEL 8eap8-bouncycastle-0:1.84.0-1.redhat_00001.1.el8eap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-5598CVSS 7.5Red Hat JBoss EAP 8.1 for RHEL 9eap8-bouncycastle-0:1.84.0-1.redhat_00001.1.el9eap.noarchPatch ↗Advisory ↗
Red HatCVE-2025-61726CVSS 7.5Zero Trust Workload Identity Manager 1.0registry.redhat.io/zero-trust-workload-identity-manager/spiffe-spire-controller-manager-rhel9@sha256:3776b0ba86480e3daa898957ef0e6f0486d0e0baf5de9413ee36ad32b3226650_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-61726CVSS 7.5Zero Trust Workload Identity Manager 1.0registry.redhat.io/zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-rhel9@sha256:5ddd2b7dcb4f2ace06627cb7d3e7d1bd59b5ca81a1ef3f01839f7f7d048a92dd_arm64Patch ↗Advisory ↗
Red HatCVE-2025-61729CVSS 7.5Red Hat Openshift Data Foundation 4.18registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:46748251be5edd0f4f95c428805ab301d780a53c0b971b29320022cb419e617c_arm64Patch ↗Advisory ↗
Red HatCVE-2025-61729CVSS 7.5Red Hat Openshift Data Foundation 4.17registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:20f88c5159c3ca97a84194252106e6b2ca97ded0184dc0057c60c28134b1e589_arm64Patch ↗Advisory ↗
Red HatCVE-2025-68121CVSS 7.4Red Hat Enterprise Linux AppStream EUS (v. 10.0)osbuild-composer-0:134.1-6.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-21441CVSS 7.5Zero Trust Workload Identity Manager 1.0registry.redhat.io/zero-trust-workload-identity-manager/spiffe-spire-controller-manager-rhel9@sha256:3776b0ba86480e3daa898957ef0e6f0486d0e0baf5de9413ee36ad32b3226650_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-21441CVSS 7.5Zero Trust Workload Identity Manager 1.0registry.redhat.io/zero-trust-workload-identity-manager/zero-trust-workload-identity-manager-rhel9@sha256:5ddd2b7dcb4f2ace06627cb7d3e7d1bd59b5ca81a1ef3f01839f7f7d048a92dd_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33036CVSS 7.5Red Hat Openshift Data Foundation 4.18registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:46748251be5edd0f4f95c428805ab301d780a53c0b971b29320022cb419e617c_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33036CVSS 7.5Red Hat Openshift Data Foundation 4.16registry.redhat.io/odf4/cephcsi-rhel9@sha256:1f667d61ae5529b52b7537b23a290cdca9e91133864f2ff7518b2480cdbc40b7_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33036CVSS 7.5Red Hat Openshift Data Foundation 4.17registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:20f88c5159c3ca97a84194252106e6b2ca97ded0184dc0057c60c28134b1e589_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1multicluster engine for Kubernetes 2.6registry.redhat.io/multicluster-engine/assisted-installer-agent-rhel8@sha256:04a8dd280a134d768f6818aa2d2af3ba9ad8f6d2226d536f763f2df3fb4816d8_s390xPatch ↗Advisory ↗
Red HatCVE-2026-34986CVSS 7.5multicluster engine for Kubernetes 2.6registry.redhat.io/multicluster-engine/assisted-service-9-rhel9@sha256:0d27fe585d871bfdd39e6ebf5331fefa0def39b26e1cb970fb0800f0db445f33_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-34986CVSS 7.5multicluster engine for Kubernetes 2.6registry.redhat.io/multicluster-engine/assisted-installer-controller-rhel8@sha256:042d4a78d0eaa6c231e83065c44c53ec1fefba469d79c40c75e3570123533aea_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-34986CVSS 7.5Red Hat Openshift Data Foundation 4.18registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:46748251be5edd0f4f95c428805ab301d780a53c0b971b29320022cb419e617c_arm64Patch ↗Advisory ↗
Red HatCVE-2026-34986CVSS 7.5Red Hat Openshift Data Foundation 4.17registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:20f88c5159c3ca97a84194252106e6b2ca97ded0184dc0057c60c28134b1e589_arm64Patch ↗Advisory ↗
Red HatCVE-2026-4800CVSS 8.1Red Hat Openshift Data Foundation 4.18registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:46748251be5edd0f4f95c428805ab301d780a53c0b971b29320022cb419e617c_arm64Patch ↗Advisory ↗
Red HatCVE-2026-4800CVSS 8.1Red Hat Openshift Data Foundation 4.16registry.redhat.io/odf4/cephcsi-rhel9@sha256:1f667d61ae5529b52b7537b23a290cdca9e91133864f2ff7518b2480cdbc40b7_amd64Patch ↗Advisory ↗
Red HatCVE-2026-4800CVSS 8.1Red Hat Openshift Data Foundation 4.17registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:20f88c5159c3ca97a84194252106e6b2ca97ded0184dc0057c60c28134b1e589_arm64Patch ↗Advisory ↗
Red HatCVE-2025-13465CVSS 8.2Red Hat OpenShift Container Platform 4.15registry.redhat.io/openshift4/ose-monitoring-plugin-rhel8@sha256:674d1ce67c4c19f832c7c48d5e3d1e2a35530b7fb5ee2c00e83443c90f18c49f_amd64Patch ↗Advisory ↗
Red HatCVE-2025-61726CVSS 7.5Red Hat OpenShift Container Platform 4.15registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:07c9197d299d5550268a2837f6f4bfc6c3b37b815e282a090cf4e4d709a3b773_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-61726CVSS 7.5Red Hat Enterprise Linux AppStream EUS (v. 10.0)gvisor-tap-vsock-6:0.8.5-2.el10_0.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-61728CVSS 7.5Red Hat OpenShift Container Platform 4.15registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:07c9197d299d5550268a2837f6f4bfc6c3b37b815e282a090cf4e4d709a3b773_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-61729CVSS 7.5Red Hat Enterprise Linux AppStream EUS (v. 10.0)gvisor-tap-vsock-6:0.8.5-2.el10_0.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-61731CVSS 8.6Red Hat OpenShift Container Platform 4.15registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:07c9197d299d5550268a2837f6f4bfc6c3b37b815e282a090cf4e4d709a3b773_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-61732CVSS 7.4Red Hat OpenShift Container Platform 4.15registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:07c9197d299d5550268a2837f6f4bfc6c3b37b815e282a090cf4e4d709a3b773_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-62718CVSS 7.0Network Observability (NETOBSERV) 1.11.1registry.redhat.io/network-observability/network-observability-console-plugin-compat-rhel9@sha256:036bb1885155decf5f9a678951122bab77d612d7a508267554a126fb90e3a384_arm64Patch ↗Advisory ↗
Red HatCVE-2025-65637CVSS 7.5Red Hat OpenShift Container Platform 4.15registry.redhat.io/openshift4/ose-cluster-kube-apiserver-rhel9-operator@sha256:001bb81ae4c70b714a5ffde62b356c88d5bd968421b706e59e08e78e5a320b37_amd64Patch ↗Advisory ↗
Red HatCVE-2025-68121CVSS 7.4Red Hat Enterprise Linux AppStream EUS (v. 10.0)gvisor-tap-vsock-6:0.8.5-2.el10_0.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-69873CVSS 7.5Red Hat OpenShift Container Platform 4.15registry.redhat.io/openshift4/ose-monitoring-plugin-rhel8@sha256:674d1ce67c4c19f832c7c48d5e3d1e2a35530b7fb5ee2c00e83443c90f18c49f_amd64Patch ↗Advisory ↗
Red HatCVE-2025-69873CVSS 7.5Network Observability (NETOBSERV) 1.11.1registry.redhat.io/network-observability/network-observability-console-plugin-compat-rhel9@sha256:036bb1885155decf5f9a678951122bab77d612d7a508267554a126fb90e3a384_arm64Patch ↗Advisory ↗
Red HatCVE-2026-25679CVSS 7.5Red Hat OpenShift Container Platform 4.15registry.redhat.io/openshift4/cloud-network-config-controller-rhel8@sha256:07c9197d299d5550268a2837f6f4bfc6c3b37b815e282a090cf4e4d709a3b773_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-25679CVSS 7.5Network Observability (NETOBSERV) 1.11.1registry.redhat.io/network-observability/network-observability-cli-rhel9@sha256:34419f34d0ae67c8f212caf1ef2676b5d2631857401e9243c3cedfb403a8b0f5_arm64Patch ↗Advisory ↗
Red HatCVE-2026-25679CVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)git-lfs-0:3.4.1-10.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-25679CVSS 7.5Red Hat Enterprise Linux AppStream EUS (v. 10.0)gvisor-tap-vsock-6:0.8.5-2.el10_0.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-25679CVSS 7.5Red Hat Enterprise Linux AppStream EUS (v.9.6)podman-5:5.4.0-20.el9_6.3.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32280CVSS 7.5Network Observability (NETOBSERV) 1.11.1registry.redhat.io/network-observability/network-observability-cli-rhel9@sha256:34419f34d0ae67c8f212caf1ef2676b5d2631857401e9243c3cedfb403a8b0f5_arm64Patch ↗Advisory ↗
Red HatCVE-2026-32280CVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)git-lfs-0:3.4.1-10.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32280CVSS 7.5Red Hat Enterprise Linux AppStream EUS (v. 10.0)gvisor-tap-vsock-6:0.8.5-2.el10_0.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32280CVSS 7.5Red Hat Enterprise Linux AppStream EUS (v.9.6)podman-5:5.4.0-20.el9_6.3.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32282CVSS 7.8Network Observability (NETOBSERV) 1.11.1registry.redhat.io/network-observability/network-observability-flowlogs-pipeline-rhel9@sha256:376f34874cc5734670e73a0830b5b4b8224ae1e8783986e9a8139eda36d59d7c_s390xPatch ↗Advisory ↗
The next page could not be added in place. The ordinary page link remains available; try it again to navigate normally.