CYBERSECURITYTRACKER
TRACKING3,612 stories653 vuln stories
Patch Day month

May 2026 vulnerabilities

A server-rendered hunting trail for May 2026: 2,180 returned patch records across 4 vendors. Browse page by page, or use “Load next” to keep adding rows without losing your place.

2,180all patches
140critical
3exploitation detected
4in CISA KEV
544tracked here
Microsoft 1,128Red Hat 1,032Cisco 19Android 1

Page 9 of 11 · records 1,601–1,800 of 2,180

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-35429 ↗2026-05-11Microsoft Edge for AndroidModerateOut-of-band0%Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2026-40416 ↗2026-05-11Microsoft Edge (Chromium-based)LowOut-of-band0%Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2026-41107 ↗2026-05-11Microsoft Edge (Chromium-based)ModerateOut-of-band1%Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
CVE-2026-42838 ↗2026-05-11Microsoft Edge (Chromium-based)ImportantOut-of-band0%Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2026-42891 ↗2026-05-11Microsoft Edge for AndroidModerateOut-of-band0%Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability
CVE-2026-7897 ↗2026-05-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7897 Use after free in Mobile
CVE-2026-7905 ↗2026-05-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7905 Insufficient validation of untrusted input in Media
CVE-2026-7912 ↗2026-05-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7912 Integer overflow in GPU
CVE-2026-7913 ↗2026-05-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7913 Insufficient policy enforcement in DevTools
CVE-2026-7915 ↗2026-05-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7915 Insufficient data validation in DevTools
CVE-2026-7931 ↗2026-05-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7931 Insufficient validation of untrusted input in iOS
CVE-2026-7941 ↗2026-05-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7941 Insufficient validation of untrusted input in Mobile
CVE-2026-7993 ↗2026-05-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7993 Insufficient validation of untrusted input in Payments
CVE-2026-8020 ↗2026-05-11Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-8020 Uninitialized Use in GPU
CVE-2026-7259 ↗2026-05-11azl3 php 8.3.29-1 on Azure Linux 3.0LowOut-of-bandNull pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()
CVE-2026-7568 ↗2026-05-11azl3 php 8.3.29-1 on Azure Linux 3.0ModerateOut-of-bandSigned integer overflow in metaphone()
CVE-2025-14179 ↗2026-05-11azl3 php 8.3.29-1 on Azure Linux 3.0ImportantOut-of-bandSQL injection in pdo_firebird via NUL bytes in quoted strings
CVE-2026-7262 ↗2026-05-11azl3 php 8.3.29-1 on Azure Linux 3.0LowOut-of-bandNULL pointer dereference in SOAP apache:Map decoder with missing <value>
CVE-2026-6735 ↗2026-05-11azl3 php 8.3.29-1 on Azure Linux 3.0ImportantOut-of-bandXSS within PHP-FPM status endpoint
CVE-2026-6722 ↗2026-05-11azl3 php 8.3.29-1 on Azure Linux 3.0CriticalOut-of-bandUse-After-Free in SOAP using Apache map
CVE-2026-7258 ↗2026-05-11azl3 php 8.3.29-1 on Azure Linux 3.0ModerateOut-of-bandOut-of-bounds read in urldecode() on NetBSD
CVE-2026-7261 ↗2026-05-11azl3 php 8.3.29-1 on Azure Linux 3.0ModerateOut-of-bandSoapServer session-persisted object use-after-free via SOAP header fault
CVE-2026-45186 ↗2026-05-11azl3 cmake 3.30.3-13 on Azure Linux 3.0LowOut-of-bandIn libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.
CVE-2026-42246 ↗2026-05-11azl3 ruby 3.3.5-8 on Azure Linux 3.0ImportantOut-of-bandnet-imap vulnerable to STARTTLS stripping via invalid response timing
CVE-2026-42256 ↗2026-05-11azl3 ruby 3.3.5-8 on Azure Linux 3.0ModerateOut-of-bandnet-imap: Denial of service via high iteration count for `SCRAM-*` authentication
CVE-2026-42258 ↗2026-05-11azl3 ruby 3.3.5-8 on Azure Linux 3.0ModerateOut-of-bandnet-imap: Command Injection via unvalidated Symbol inputs
CVE-2026-42257 ↗2026-05-11azl3 ruby 3.3.5-8 on Azure Linux 3.0ModerateOut-of-bandnet-imap: Command Injection via "raw" arguments to multiple commands
CVE-2026-41889 ↗2026-05-10azl3 keda 2.14.1-11 on Azure Linux 3.0LowOut-of-bandpgx: SQL Injection via placeholder confusion with dollar quoted string literals
CVE-2026-33079 ↗2026-05-10azl3 python-mistune 3.0.2-1 on Azure Linux 3.0ImportantOut-of-bandMistune ReDoS in LINK_TITLE_RE allows denial of service with crafted Markdown titles
CVE-2026-42501 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ImportantOut-of-bandMalicious module proxy can bypass checksum database in cmd/go
CVE-2026-42499 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ImportantOut-of-bandQuadratic string concatenation in consumePhrase in net/mail
CVE-2026-39836 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ImportantOut-of-bandPanic in Dial and LookupPort when handling NUL byte on Windows in net
CVE-2026-39826 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ModerateOut-of-bandEscaper bypass leads to XSS in html/template
CVE-2026-39825 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ModerateOut-of-bandReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil
CVE-2026-39823 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ModerateOut-of-bandBypass of meta content URL escaping causes XSS in html/template
CVE-2026-39820 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ImportantOut-of-bandQuadratic string concatentation in consumeComment in net/mail
CVE-2026-39819 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ModerateOut-of-bandInvoking "go bug" follows symlinks in predictable temporary filenames in cmd/go
CVE-2026-39817 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ModerateOut-of-bandInvoking "go tool pack" does not sanitize output paths in cmd/go
CVE-2026-33814 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ImportantOut-of-bandInfinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
CVE-2026-33811 ↗2026-05-10azl3 golang 1.25.9-1 on Azure Linux 3.0ImportantOut-of-bandCrash when handling long CNAME response in net
CVE-2026-44656 ↗2026-05-10azl3 vim 9.2.0392-1 on Azure Linux 3.0ModerateOut-of-bandVim: OS Command Injection via 'path' completion
CVE-2026-45130 ↗2026-05-10azl3 vim 9.2.0392-1 on Azure Linux 3.0ModerateOut-of-bandVim: Heap Buffer Overflow in spell file loading
CVE-2026-6666 ↗2026-05-10azl3 pgbouncer 1.25.1-1 on Azure Linux 3.0ModerateOut-of-bandPgBouncer crash in kill_pool_logins_server_error
CVE-2026-6667 ↗2026-05-10azl3 pgbouncer 1.25.1-1 on Azure Linux 3.0ModerateOut-of-bandPgBouncer missing authorization check in KILL_CLIENT admin command
CVE-2026-6665 ↗2026-05-10azl3 pgbouncer 1.25.1-1 on Azure Linux 3.0ImportantOut-of-bandPgBouncer buffer overflow in SCRAM
CVE-2026-6664 ↗2026-05-10azl3 pgbouncer 1.25.1-1 on Azure Linux 3.0ImportantOut-of-band1%VulnCheckPgBouncer integer overflow in PgBouncer network packet parsing
CVE-2026-33846 ↗2026-05-09azl3 gnutls 3.8.3-11 on Azure Linux 3.0ModerateOut-of-bandGnutls: gnutls: denial of service via heap buffer overflow in dtls handshake fragment reassembly
CVE-2026-37459 ↗2026-05-09azl3 frr 10.5.0-3 on Azure Linux 3.0ModerateOut-of-bandAn integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
CVE-2026-37458 ↗2026-05-09azl3 frr 10.5.0-3 on Azure Linux 3.0ModerateOut-of-bandMissing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message.
CVE-2026-43308 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandbtrfs: don't BUG() on unexpected delayed ref type in run_one_delayed_ref()
CVE-2026-43421 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-bandusb: gadget: f_ncm: Fix net_device lifecycle with device_move
CVE-2026-43311 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandsoc/tegra: pmc: Fix unsafe generic_handle_irq() call
CVE-2026-43398 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-banddrm/amdgpu: add upper bound check on user inputs in wait ioctl
CVE-2026-43292 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandmm/vmalloc: prevent RCU stalls in kasan_release_vmalloc_node
CVE-2026-43353 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-bandi3c: mipi-i3c-hci: Fix race in DMA ring dequeue
CVE-2026-43294 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm: renesas: rz-du: mipi_dsi: fix kernel panic when rebooting for some panels
CVE-2026-43310 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandmedia: verisilicon: Avoid G2 bus error while decoding H.264 and HEVC
CVE-2026-43400 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-banddrm/amdgpu: add upper bound check on user inputs in signal ioctl
CVE-2026-43299 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandbtrfs: do not ASSERT() when the fs flips RO inside btrfs_repair_io_failure()
CVE-2026-43298 ↗2026-05-09azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/amdgpu: Skip vcn poison irq release on VF
CVE-2026-43305 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Fix mismatched unlock for DMUB HW lock in HWSS fast path
CVE-2026-43456 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandbonding: fix type confusion in bond_setup_by_slave()
CVE-2026-43321 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-bandbpf: Properly mark live registers for indirect jumps
CVE-2026-43344 ↗2026-05-09azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandperf/x86/intel/uncore: Fix die ID init and look up bugs
CVE-2026-43303 ↗2026-05-09azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-bandmm/page_alloc: clear page->private in free_pages_prepare()
CVE-2026-43319 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandspi: spidev: fix lock inversion between spi_lock and buf_lock
CVE-2026-43317 ↗2026-05-09azl3 kernel 6.6.138.1-1 on Azure Linux 3.0N/AOut-of-bandmost: core: fix leak on early registration failure
CVE-2026-43443 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-bandASoC: amd: acp-mach-common: Add missing error check for clock acquisition
CVE-2026-43306 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandbpf: crypto: Use the correct destructor kfunc type
CVE-2026-43320 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-banddrm/amd/display: Fix dsc eDP issue
CVE-2026-43331 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandx86/kexec: Disable KCOV instrumentation after load_segments()
CVE-2026-43300 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-banddrm/panel: Fix a possible null-pointer dereference in jdi_panel_dsi_remove()
CVE-2026-43352 ↗2026-05-09azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ModerateOut-of-bandi3c: mipi-i3c-hci: Correct RING_CTRL_ABORT handling in DMA dequeue
CVE-2026-43284 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-band93%VulnCheckxfrm: esp: avoid in-place decrypt on shared skb frags
CVE-2025-71299 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandspi: cadence-quadspi: Parse DT for flashes with the rest of the DT parsing
CVE-2026-43416 ↗2026-05-09azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandpowerpc, perf: Check that current->mm is alive before getting user callchain
CVE-2026-43309 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandmd raid: fix hang when stopping arrays with metadata through dm-raid
CVE-2026-43318 ↗2026-05-09azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-banddrm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify
CVE-2025-71302 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-banddrm/panthor: fix for dma-fence safe access rules
CVE-2026-43338 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ModerateOut-of-bandbtrfs: reserve enough transaction items for qgroup ioctls
CVE-2026-43474 ↗2026-05-09azl3 kernel 6.6.137.1-2 on Azure Linux 3.0N/AOut-of-bandfs: init flags_valid before calling vfs_fileattr_get
CVE-2026-25589 ↗2026-05-08azl3 valkey 8.0.7-1 on Azure Linux 3.0ImportantOut-of-bandRedisBloom RESTORE invalid memory access may allow remote code execution
CVE-2026-25588 ↗2026-05-08azl3 valkey 8.0.7-1 on Azure Linux 3.0ImportantOut-of-bandRedisTimeSeries RESTORE invalid memory access may allow remote code execution
CVE-2026-23479 ↗2026-05-08azl3 valkey 8.0.7-1 on Azure Linux 3.0ImportantOut-of-bandredis-server use-after-free in unblock client flow may allow remote code execution
CVE-2026-31718 ↗2026-05-08azl3 kernel 6.6.137.1-2 on Azure Linux 3.0CriticalOut-of-bandksmbd: fix use-after-free in __ksmbd_close_fd() via durable scavenger
CVE-2026-31717 ↗2026-05-08azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ImportantOut-of-bandksmbd: validate owner of durable handle on reconnect
CVE-2026-23631 ↗2026-05-08azl3 valkey 8.0.7-1 on Azure Linux 3.0ModerateOut-of-bandredis-server Lua use-after-free may allow remote code execution
CVE-2026-25243 ↗2026-05-08azl3 valkey 8.0.9-1 on Azure Linux 3.0ImportantOut-of-bandredis-server RESTORE invalid memory access may allow remote code execution
CVE-2026-41673 ↗2026-05-08azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandxmldom: Denial of service via uncontrolled recursion in XML serialization
CVE-2026-41675 ↗2026-05-08azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandxmldom: XML node injection through unvalidated processing instruction serialization
CVE-2026-41674 ↗2026-05-08azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandxmldom: XML injection through unvalidated DocumentType serialization
CVE-2026-41672 ↗2026-05-08azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-bandxmldom: XML node injection through unvalidated comment serialization
CVE-2026-43869 ↗2026-05-08azl3 thrift 0.15.0-5 on Azure Linux 3.0ImportantOut-of-bandApache Thrift: TSSLTransportFactory.java hostname verification
CVE-2026-7896 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7896 Integer overflow in Blink
CVE-2026-26129 ↗2026-05-07Microsoft 365 Copilot's Business ChatCriticalOut-of-band1%M365 Copilot Information Disclosure Vulnerability
CVE-2026-26164 ↗2026-05-07Microsoft 365 Copilot's Business ChatCriticalOut-of-band1%M365 Copilot Information Disclosure Vulnerability
CVE-2026-32207 ↗2026-05-07Azure Machine LearningCriticalOut-of-band1%Azure Machine Learning Notebook Spoofing Vulnerability
CVE-2026-33109 ↗2026-05-07Azure Managed Instance for Apache CassandraCriticalOut-of-band1%Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
CVE-2026-33111 ↗2026-05-07Copilot Chat (Microsoft Edge)CriticalOut-of-band1%Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
CVE-2026-33821 ↗2026-05-07Dynamics 365 Customer InsightsCriticalOut-of-band1%Microsoft Dynamics 365 Customer Insights Elevation of Privilege Vulnerability
CVE-2026-33823 ↗2026-05-07Microsoft TeamsCriticalOut-of-band1%Microsoft Team Events Portal Information Disclosure Vulnerability
CVE-2026-33844 ↗2026-05-07Azure Managed Instance for Apache CassandraCriticalOut-of-band1%Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability
CVE-2026-34327 ↗2026-05-07Microsoft Partner CenterCriticalOut-of-band1%Microsoft Partner Center Spoofing Vulnerability
CVE-2026-35428 ↗2026-05-07Azure Cloud ShellCriticalOut-of-band1%Azure Cloud Shell Spoofing Vulnerability
CVE-2026-35435 ↗2026-05-07Azure AI FoundryCriticalOut-of-band1%More likelyAzure AI Foundry Elevation of Privilege Vulnerability
CVE-2026-40379 ↗2026-05-07Microsoft Entra IDCriticalOut-of-band1%Azure Entra ID Spoofing Vulnerability
CVE-2026-41105 ↗2026-05-07Azure Monitor Action Group notification systemCriticalOut-of-band1%Azure Monitor Action Group Notification System Elevation of Privilege Vulnerability
CVE-2026-42826 ↗2026-05-07Azure DevOpsCriticalOut-of-band1%Azure DevOps Information Disclosure Vulnerability
CVE-2026-7898 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7898 Use after free in Chromoting
CVE-2026-7899 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7899 Out of bounds read and write in V8
CVE-2026-7900 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7900 Heap buffer overflow in ANGLE
CVE-2026-7901 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7901 Use after free in ANGLE
CVE-2026-7902 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7902 Out of bounds memory access in V8
CVE-2026-7903 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7903 Integer overflow in ANGLE
CVE-2026-7904 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7904 Out of bounds read in Fonts
CVE-2026-7906 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7906 Use after free in SVG
CVE-2026-7907 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7907 Use after free in DOM
CVE-2026-7908 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7908 Use after free in Fullscreen
CVE-2026-7909 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7909 Inappropriate implementation in ServiceWorker
CVE-2026-7910 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7910 Use after free in Views
CVE-2026-7911 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7911 Use after free in Aura
CVE-2026-7914 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7914 Type Confusion in Accessibility
CVE-2026-7916 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7916 Insufficient data validation in InterestGroups
CVE-2026-7917 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7917 Use after free in Fullscreen
CVE-2026-7918 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7918 Use after free in GPU
CVE-2026-7919 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7919 Use after free in Aura
CVE-2026-7920 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7920 Use after free in Skia
CVE-2026-7921 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7921 Use after free in Passwords
CVE-2026-7922 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7922 Use after free in ServiceWorker
CVE-2026-7923 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7923 Out of bounds write in Skia
CVE-2026-7924 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7924 Uninitialized Use in Dawn
CVE-2026-7925 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7925 Use after free in Chromoting
CVE-2026-7926 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7926 Use after free in PresentationAPI
CVE-2026-7927 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7927 Type Confusion in Runtime
CVE-2026-7928 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7928 Use after free in WebRTC
CVE-2026-7929 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7929 Use after free in MediaRecording
CVE-2026-7930 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-bandChromium: CVE-2026-7930 Insufficient validation of untrusted input in Cookies
CVE-2026-7932 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7932 Insufficient policy enforcement in Downloads
CVE-2026-7933 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7933 Out of bounds read in WebCodecs
CVE-2026-7934 ↗2026-05-07Microsoft Edge (Chromium-based)N/AOut-of-band0%Chromium: CVE-2026-7934 Insufficient validation of untrusted input in Popup Blocker

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-42041CVSS 8.2Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:4fcc3d48a763c1cc51b2cd253a4862c7bf99cd614163ef2f80d5a2f8968066a1_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-42043CVSS 7.2Red Hat OpenShift Service Mesh 2.6registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel8@sha256:251acc1dcd2446bff4a6ea247e991c3c9186be784ac604df10efec1b312a8c87_arm64Patch ↗Advisory ↗
Red HatCVE-2026-42043CVSS 7.2Red Hat OpenShift Service Mesh 3.1registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:0fe6b8e81892d6e45a24319338149ba5f588a0a42c6a7e013d70832b4e4d00d5_arm64Patch ↗Advisory ↗
Red HatCVE-2026-42043CVSS 7.2Red Hat OpenShift Service Mesh 3.0registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:246c34d2e769f9f40e5879bf335ce7db614442ade7733d4ac52e10a48d280843_s390xPatch ↗Advisory ↗
Red HatCVE-2026-42043CVSS 7.2Red Hat OpenShift Service Mesh 3.2registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:670dbb0cdefd1e46fc6919d4b232f88b3e39599b6ea90602476fd84308986bca_arm64Patch ↗Advisory ↗
Red HatCVE-2026-42043CVSS 7.2Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:4fcc3d48a763c1cc51b2cd253a4862c7bf99cd614163ef2f80d5a2f8968066a1_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-42044CVSS 7.4Red Hat OpenShift Service Mesh 3.1registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:0fe6b8e81892d6e45a24319338149ba5f588a0a42c6a7e013d70832b4e4d00d5_arm64Patch ↗Advisory ↗
Red HatCVE-2026-42044CVSS 7.4Red Hat OpenShift Service Mesh 3.0registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:246c34d2e769f9f40e5879bf335ce7db614442ade7733d4ac52e10a48d280843_s390xPatch ↗Advisory ↗
Red HatCVE-2026-42044CVSS 7.4Red Hat OpenShift Service Mesh 3.2registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:670dbb0cdefd1e46fc6919d4b232f88b3e39599b6ea90602476fd84308986bca_arm64Patch ↗Advisory ↗
Red HatCVE-2026-42044CVSS 7.4Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/kiali-ossmc-rhel9@sha256:4fcc3d48a763c1cc51b2cd253a4862c7bf99cd614163ef2f80d5a2f8968066a1_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-42498CVSS 6.5Red Hat Hardened Imagestomcat10-main@noarchPatch ↗Advisory ↗
Red HatCVE-2026-43512CVSS 6.5Red Hat Hardened Imagestomcat10-main@noarchPatch ↗Advisory ↗
Red HatCVE-2026-43514CVSS 3.7Red Hat Hardened Imagestomcat10-main@noarchPatch ↗Advisory ↗
Red HatCVE-2026-43515CVSS 5.4Red Hat Hardened Imagestomcat10-main@noarchPatch ↗Advisory ↗
Red HatCVE-2026-44927CVSS 2.2Red Hat Hardened Imagesuriparser-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-44928CVSS 5.3Red Hat Hardened Imagesuriparser-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2025-13033CVSS 7.5Red Hat Ceph Storage 8.1registry.redhat.io/rhceph/grafana-rhel9@sha256:3d4903b8dbe33464c05ce219ee2e945bf1be169efbed73caee5185883c9df508_amd64Patch ↗Advisory ↗
Red HatCVE-2025-47913CVSS 7.5Red Hat Enterprise Linux AppStream E4S (v.9.0)buildah-1:1.26.11-1.el9_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-47914CVSS 5.3Red Hat Ceph Storage 8.1registry.redhat.io/rhceph/grafana-rhel9@sha256:3d4903b8dbe33464c05ce219ee2e945bf1be169efbed73caee5185883c9df508_amd64Patch ↗Advisory ↗
Red HatCVE-2025-58181CVSS 5.3Red Hat Ceph Storage 8.1registry.redhat.io/rhceph/grafana-rhel9@sha256:3d4903b8dbe33464c05ce219ee2e945bf1be169efbed73caee5185883c9df508_amd64Patch ↗Advisory ↗
Red HatCVE-2025-61726CVSS 7.5Red Hat Satellite 6.18registry.redhat.io/satellite/iop-ingress-rhel9@sha256:f09b73e899aa040a997d14920f6954cd6e436997b55f8dea0dbd00d13e462bfb_amd64Patch ↗Advisory ↗
Red HatCVE-2025-61726CVSS 7.5Red Hat Enterprise Linux AppStream E4S (v.9.0)buildah-1:1.26.11-1.el9_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-61729CVSS 7.5Red Hat Ceph Storage 8.1registry.redhat.io/rhceph/grafana-rhel9@sha256:3d4903b8dbe33464c05ce219ee2e945bf1be169efbed73caee5185883c9df508_amd64Patch ↗Advisory ↗
Red HatCVE-2025-61729CVSS 7.5Red Hat Enterprise Linux AppStream E4S (v.9.0)buildah-1:1.26.11-1.el9_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-64718CVSS 5.3Red Hat Ceph Storage 8.1registry.redhat.io/rhceph/grafana-rhel9@sha256:3d4903b8dbe33464c05ce219ee2e945bf1be169efbed73caee5185883c9df508_amd64Patch ↗Advisory ↗
Red HatCVE-2025-64756CVSS 7.5Red Hat Ceph Storage 8.1registry.redhat.io/rhceph/grafana-rhel9@sha256:3d4903b8dbe33464c05ce219ee2e945bf1be169efbed73caee5185883c9df508_amd64Patch ↗Advisory ↗
Red HatCVE-2025-65637CVSS 7.5Red Hat Enterprise Linux AppStream E4S (v.9.0)oci-seccomp-bpf-hook-0:1.2.10-1.el9_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-65637CVSS 7.5Red Hat Enterprise Linux AppStream E4S (v.9.0)skopeo-2:1.8.0-4.1.el9_0.3.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-68121CVSS 7.4Red Hat Enterprise Linux AppStream E4S (v.9.0)buildah-1:1.26.11-1.el9_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-68156CVSS 7.5Red Hat Ceph Storage 8.1registry.redhat.io/rhceph/grafana-rhel9@sha256:3d4903b8dbe33464c05ce219ee2e945bf1be169efbed73caee5185883c9df508_amd64Patch ↗Advisory ↗
Red HatCVE-2026-25679CVSS 7.5Red Hat Enterprise Linux AppStream E4S (v.9.0)buildah-1:1.26.11-1.el9_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-27140CVSS 9.0Red Hat Enterprise Linux AppStream EUS (v.9.6)go-toolset-0:1.25.9-1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-27140CVSS 9.0Red Hat Enterprise Linux AppStream EUS (v. 10.0)go-toolset-0:1.25.9-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-27143CVSS 8.1Red Hat Enterprise Linux AppStream EUS (v.9.6)go-toolset-0:1.25.9-1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-27143CVSS 8.1Red Hat Enterprise Linux AppStream EUS (v. 10.0)go-toolset-0:1.25.9-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-27144CVSS 8.1Red Hat Enterprise Linux AppStream EUS (v.9.6)go-toolset-0:1.25.9-1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-27144CVSS 8.1Red Hat Enterprise Linux AppStream EUS (v. 10.0)go-toolset-0:1.25.9-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32280CVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)rhc-1:0.2.5-7.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32280CVSS 7.5Red Hat Enterprise Linux AppStream EUS (v.9.6)go-toolset-0:1.25.9-1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32280CVSS 7.5Red Hat Enterprise Linux AppStream EUS (v. 10.0)go-toolset-0:1.25.9-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32280CVSS 7.5Red Hat Enterprise Linux Server (v. 7 ELS)host-metering-0:1.4.0-7.el7_9.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9Red Hat Enterprise Linux AppStream EUS (v.9.6)go-toolset-0:1.25.9-1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9Red Hat Enterprise Linux AppStream EUS (v. 10.0)go-toolset-0:1.25.9-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9Red Hat Enterprise Linux Server (v. 7 ELS)host-metering-0:1.4.0-7.el7_9.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-32282CVSS 7.8Red Hat Enterprise Linux AppStream (v. 8)rhc-1:0.2.5-7.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32282CVSS 7.8Red Hat Enterprise Linux AppStream EUS (v.9.6)go-toolset-0:1.25.9-1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32282CVSS 7.8Red Hat Enterprise Linux AppStream EUS (v. 10.0)go-toolset-0:1.25.9-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32282CVSS 7.8Red Hat Enterprise Linux Server (v. 7 ELS)host-metering-0:1.4.0-7.el7_9.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-32283CVSS 7.5Red Hat Enterprise Linux AppStream (v. 8)rhc-1:0.2.5-7.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32283CVSS 7.5Red Hat Enterprise Linux AppStream EUS (v.9.6)go-toolset-0:1.25.9-1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32283CVSS 7.5Red Hat Enterprise Linux AppStream EUS (v. 10.0)go-toolset-0:1.25.9-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32283CVSS 7.5Red Hat Enterprise Linux Server (v. 7 ELS)host-metering-0:1.4.0-7.el7_9.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-32283CVSS 7.5Red Hat Enterprise Linux AppStream E4S (v.9.0)buildah-1:1.26.11-1.el9_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-40898CVSS 7.5Red Hat Hardened Imagestrivy-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-41889CVSS 5.9Red Hat Hardened Imagesgo-fdo-server-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-44432CVSS 7.5Red Hat Hardened Imagestrivy-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-45287CVSS 4.0Red Hat Hardened Imagestrivy-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-53489CVSS 6.5Red Hat Hardened Imagestrivy-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-53492CVSS 8.2Red Hat Hardened Imagestrivy-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2025-65637CVSS 7.5Red Hat OpenShift Container Platform 4.12openshift-0:4.12.0-202604271501.p2.gedc7ba9.assembly.stream.el8.srcPatch ↗Advisory ↗