CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Vulnerabilities

June 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 0 vulnerabilities with exploitation detected in the wild this month. This defender-focused view covers 2,291 vulnerabilities across 5,850 returned patch records from 4 vendors. Filter the complete month, or browse the static page trail without JavaScript.

5,850all patch recordsClear filters263criticalShow these records0Microsoft exploitation detectedShow these records2Microsoft in the Known Exploited Vulnerabilities catalogShow these records1,488tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

My Stack only keeps records whose vendor you have pinned. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 21 of 30 · records 4,001 to 4,200 of 5,850

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-52970 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nft_ct: fix missing expect put in obj eval
CVE-2026-53226 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablegpio: rockchip: fix generic IRQ chip leak on remove
CVE-2026-53048 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablegfs2: prevent NULL pointer dereference during unmount
CVE-2026-53128 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrbd: Balance RCU calls in drbd_adm_dump_devices()
CVE-2026-53037 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableHID: usbhid: fix deadlock in hid_post_reset()
CVE-2026-53183 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemptcp: allow subflow rcv wnd to shrink
CVE-2026-52925 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevrf: Fix a potential NPD when removing a port from a VRF
CVE-2026-53208 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig
CVE-2026-53066 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/sun4i: backend: fix error pointer dereference
CVE-2026-53041 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableocfs2: fix listxattr handling when the buffer is full
CVE-2026-53064 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledm cache: fix null-deref with concurrent writes in passthrough mode
CVE-2026-53258 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: fix leak if split 6 GHz scanning fails
CVE-2026-52969 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableKVM: Reject wrapped offset in kvm_reset_dirty_gfn()
CVE-2026-53109 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepowerpc/pgtable-frag: Fix bad page state in pte_frag_destroy
CVE-2026-53047 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableefi/capsule-loader: fix incorrect sizeof in phys array reallocation
CVE-2026-53220 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: revalidate bridge ports
CVE-2026-53011 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/sched: taprio: fix use-after-free in advance_sched() on schedule switch
CVE-2026-53110 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailables390/bpf: Zero-extend bpf prog return values and kfunc arguments
CVE-2026-52937 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR
CVE-2026-52977 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefutex: Prevent lockup in requeue-PI during signal/ timeout wakeup
CVE-2026-53190 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait()
CVE-2026-53132 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevsock/virtio: fix potential unbounded skb queue
CVE-2026-53096 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path
CVE-2026-53245 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr
CVE-2026-53061 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledm cache: fix dirty mapping checking in passthrough mode switching
CVE-2026-52961 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size
CVE-2026-53107 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: libertas: don't kill URBs in interrupt context
CVE-2026-53122 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: fix deadlock between reflink and transaction commit when using flushoncommit
CVE-2026-53168 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefuse: reject fuse_notify() pagecache ops on directories
CVE-2026-52963 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALSA: usb-audio: Bound MIDI endpoint descriptor scans
CVE-2026-53214 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableipv6: Fix a potential NPD in cleanup_prefix_route()
CVE-2026-52992 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefs/adfs: validate nzones in adfs_validate_bblk()
CVE-2026-53035 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf, sockmap: Fix af_unix iter deadlock
CVE-2026-52936 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecrypto: jitterentropy - replace long-held spinlock with mutex
CVE-2026-53237 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablegpio: mvebu: fix NULL pointer dereference in suspend/resume
CVE-2026-53073 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error
CVE-2026-53113 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: ath11k: fix memory leaks in beacon template setup
CVE-2026-52929 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesctp: stream: fully roll back denied add-stream state
CVE-2026-53148 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablethunderbolt: Clamp XDomain response data copy to allocation size
CVE-2026-53218 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nft_exthdr: fix register tracking for F_PRESENT flag
CVE-2026-52954 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibceph: handle rbtree insertion error in decode_choose_args()
CVE-2026-53166 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefutex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlock
CVE-2026-53032 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Fix NULL deref in map_kptr_match_type for scalar regs
CVE-2026-53093 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: brcmfmac: Fix error pointer dereference
CVE-2026-53179 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablestaging: rtl8723bs: fix buffer over-read in rtw_update_protection
CVE-2026-52946 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling
CVE-2026-53265 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledm cache policy smq: check allocation under invalidate lock
CVE-2026-53003 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepppoe: drop PFC frames
CVE-2026-53255 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: MGMT: validate advertising TLV before type checks
CVE-2026-53015 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableerofs: unify lcn as u64 for 32-bit platforms
CVE-2026-53098 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work()
CVE-2026-53076 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Fix OOB in pcpu_init_value
CVE-2026-53078 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Fix same-register dst/src OOB read and pointer leak in sock_ops
CVE-2026-52968 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableKVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic
CVE-2026-53082 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: hamradio: 6pack: fix uninit-value in sixpack_receive_buf
CVE-2026-53133 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableRDMA/umem: Fix truncation for block sizes >= 4G
CVE-2026-52920 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: xt_policy: fix strict mode inbound policy matching
CVE-2026-52996 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableksmbd: fix durable fd leak on ClientGUID mismatch in durable v2 open
CVE-2026-52974 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: tls: fix strparser anchor skb leak on offload RX setup failure
CVE-2026-52960 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableceph: put folios not suitable for writeback
CVE-2026-53192 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALSA: timer: Fix UAF at snd_timer_user_params()
CVE-2026-53072 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER
CVE-2026-53209 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: hci_sync: reject oversized Broadcast Announcement prepend
CVE-2026-53063 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledm cache: fix write hang in passthrough mode
CVE-2026-52957 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibceph: Fix potential null-ptr-deref in decode_choose_args()
CVE-2026-53275 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableipv6: mcast: Fix use-after-free when processing MLD queries
CVE-2026-53060 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledm cache metadata: fix memory leak on metadata abort retry
CVE-2026-52942 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nf_log: validate MAC header was set before dumping it
CVE-2026-53139 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/v3d: Skip CSD when it has zeroed workgroups
CVE-2026-53267 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nft_ct: bail out on template ct in get eval
CVE-2026-53178 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablestaging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction
CVE-2026-53249 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableipv4: restrict IPOPT_SSRR and IPOPT_LSRR options
CVE-2026-53177 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebnxt_en: Fix NULL pointer dereference
CVE-2026-53184 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableudp: clear skb->dev before running a sockmap verdict
CVE-2026-52918 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: serialize accept_q access
CVE-2026-53120 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablePCI: use generic driver_override infrastructure
CVE-2026-53158 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemisc: fastrpc: Fix NULL pointer dereference in rpmsg callback
CVE-2025-15661 ↗azl3 libssh2 1.11.1-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c
CVE-2026-53181 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevsock/vmci: fix sk_ack_backlog leak on failed handshake
CVE-2026-47242 ↗azl3 ruby 3.3.5-8 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableNet::IMAP: Command Injection via ID command argument
CVE-2026-47240 ↗azl3 ruby 3.3.5-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableNet::IMAP: Command Injection via non-synchronizing literal in "raw" argument
CVE-2026-53163 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelocking/rtmutex: Skip remove_waiter() when waiter is not enqueued
CVE-2026-53022 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableplatform/x86: dell-wmi-sysman: bound enumeration string aggregation
CVE-2026-53150 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablethunderbolt: Reject zero-length property entries in validator
CVE-2026-53115 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebus: fsl-mc: use generic driver_override infrastructure
CVE-2026-53254 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: RFCOMM: validate skb length in MCC handlers
CVE-2026-53013 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemacvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF
CVE-2026-53149 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablethunderbolt: Bound root directory content to block size
CVE-2026-3196 ↗azl3 qemu 9.1.0-8 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableQemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation
CVE-2026-52916 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebatman-adv: frag: disallow unicast fragment in fragment
CVE-2026-53161 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemisc: fastrpc: fix use-after-free of fastrpc_user in workqueue context
CVE-2026-0864 ↗azl3 python3 3.12.9-11 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableConfiguration Injection via Carriage Return (\r) in write() method
CVE-2026-9539 ↗azl3 libslirp 4.7.0-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibslirp TCP URG OOB Read Information Leak
CVE-2026-53126 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableblk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current()
CVE-2026-52956 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibceph: Fix potential out-of-bounds access in __ceph_x_decrypt()
CVE-2026-52915 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: ip6t_hbh: reject oversized option lists
CVE-2026-47770 ↗azl3 jq 1.7.1-6 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablejq: stack overflow in deep structural equality
CVE-2026-53065 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableASoC: sti: use managed regmap_field allocations
CVE-2026-53182 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: nl80211: reject oversized EMA RNR lists
CVE-2026-53138 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Bound VBIOS record-chain walk loops
CVE-2026-54679 ↗azl3 jq 1.7.1-6 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablejq: potential integer overflow in jvp_string_append
CVE-2026-53264 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/sched: act_api: use RCU with deferred freeing for action lifecycle
CVE-2026-53274 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS
CVE-2026-53146 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablethunderbolt: Limit XDomain response copy to actual frame size
CVE-2026-52917 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesctp: diag: reject stale associations in dump_one path
CVE-2026-56131 ↗azl3 cmake 3.30.3-13 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
CVE-2026-53147 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablethunderbolt: Validate XDomain request packet size before type cast
CVE-2026-53118 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevdpa: use generic driver_override infrastructure
CVE-2026-53094 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Fix stale offload->prog pointer after constant blinding
CVE-2026-53112 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet
CVE-2026-56412 ↗azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.
CVE-2026-52975 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebonding: 3ad: implement proper RCU rules for port->aggregator
CVE-2026-53137 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size
CVE-2026-53230 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list
CVE-2026-56410 ↗azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablexmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-53236 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletcp: restrict SO_ATTACH_FILTER to priv users
CVE-2026-52933 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableio_uring/poll: fix signed comparison in io_poll_get_ownership()
CVE-2026-56409 ↗azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablexmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
CVE-2026-53012 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenexthop: fix IPv6 route referencing IPv4 nexthop
CVE-2026-56411 ↗azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablexmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
CVE-2026-53024 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablegreybus: raw: fix use-after-free if write is called after disconnect
CVE-2026-53238 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetlabel: validate unlabeled address and mask attribute lengths
CVE-2026-56132 ↗azl3 cmake 3.30.3-13 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableIn libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.
CVE-2026-55653 ↗azl3 openssh 9.8p1-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableOpenssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service
CVE-2026-55655 ↗azl3 openssh 9.8p1-6 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableOpenssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions
CVE-2026-53242 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
CVE-2026-56403 ↗azl3 python3 3.12.9-11 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibexpat before 2.8.2 has an integer overflow in storeAtts.
CVE-2026-53213 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/vc4: fix krealloc() memory leak
CVE-2026-53071 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp
CVE-2026-53270 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableipvs: clear the svc scheduler ptr early on edit
CVE-2026-53227 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: openvswitch: fix possible kfree_skb of ERR_PTR
CVE-2026-56407 ↗azl3 python3 3.12.9-11 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
CVE-2026-52981 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableneigh: let neigh_xmit take skb ownership
CVE-2026-52921 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: ipset: stop hash:* range iteration at end
CVE-2026-48142 ↗azl3 nginx 1.28.3-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableNGINX ngx_http_charset_module vulnerability
CVE-2026-53212 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nft_tunnel: fix use-after-free on object destroy
CVE-2026-53129 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefs/mbcache: cancel shrink work before destroying the cache
CVE-2026-56406 ↗azl3 cmake 3.30.3-13 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
CVE-2026-13201 ↗azl3 kubevirt 1.8.4-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableKubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level vm disruption
CVE-2026-53207 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison
CVE-2026-53059 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledm log: fix out-of-bounds write due to region_count overflow
CVE-2026-56404 ↗azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibexpat before 2.8.2 has an integer overflow in addBinding.
CVE-2026-12725 ↗azl3 dnsmasq 2.92-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableDnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies
CVE-2026-12969 ↗azl3 dnsmasq 2.92-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableDnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation
CVE-2026-53136 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Clamp VBIOS HDMI retimer register count to array size
CVE-2026-53239 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablexfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()
CVE-2026-56405 ↗azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibexpat before 2.8.2 has an integer overflow in getAttributeId.
CVE-2026-52953 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableiommu/vt-d: Fix oops due to out of scope access
CVE-2026-56115 ↗azl3 dhcpcd 10.0.8-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBootimus 0.1.70 Broken Access Control via JWTMiddleware Authorization Bypass
CVE-2026-53195 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableUSB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()
CVE-2026-53021 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: target: core: Fix integer overflow in UNMAP bounds check
CVE-2026-56116 ↗azl3 dhcpcd 10.0.8-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledhcpcd Memory Leak DoS via IPv6 Router Advertisement Handling
CVE-2026-52948 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablei2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl
CVE-2026-4367 ↗azl3 libXpm 3.5.17-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableLibxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-42250CVSS 5.0Red Hat Hardened Imagesbzip2-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4367CVSS 5.5Red Hat Hardened Imageslibxpm-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-57452CVSS 4.7Red Hat Hardened Imagesvim-0:9.2.725-1.hum1@srcPatch ↗Advisory ↗
Red HatCVE-2026-57455CVSS 4.7Red Hat Hardened Imagesvim-0:9.2.725-1.hum1@srcPatch ↗Advisory ↗
Red HatCVE-2023-40403CVSS 6.5Red Hat Enterprise Linux AppStream E4S (v.9.2)libxslt-0:1.1.34-12.el9_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-10911CVSS 5.5Red Hat Enterprise Linux AppStream EUS (v.9.6)libxslt-0:1.1.34-13.el9_6.2.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-10911CVSS 5.5Red Hat Enterprise Linux AppStream EUS (v. 10.0)libxslt-0:1.1.39-8.el10_0.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-10911CVSS 5.5Red Hat Enterprise Linux AppStream E4S (v.9.2)libxslt-0:1.1.34-12.el9_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-10911CVSS 5.5Red Hat Enterprise Linux AppStream E4S (v.9.4)libxslt-0:1.1.34-15.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-10911CVSS 5.5Red Hat Enterprise Linux AppStream AUS (v.8.4)libxslt-debuginfo-0:1.1.32-8.el8_4.1.i686Patch ↗Advisory ↗
Red HatCVE-2025-10911CVSS 5.5Red Hat Enterprise Linux AppStream E4S (v.8.8)libxslt-debuginfo-0:1.1.32-8.el8_8.1.i686Patch ↗Advisory ↗
Red HatCVE-2025-15661CVSS 6.5Red Hat Hardened Imageslibssh2-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12302CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.12.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12305CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.12.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12306CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.12.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12307CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.12.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12308CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.12.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12309CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.12.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12310CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.12.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12311CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.12.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12312CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.12.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12313CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.12.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12314CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.12.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12327CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.12.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12330CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.12.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-22773CVSS 6.5Red Hat AI Inference Server 3.3registry.redhat.io/rhaiis/vllm-spyre-rhel9@sha256:681d191e22994e4da2d4844219e2401ee363d4b3524cd19bb00076dce685a36a_s390xPatch ↗Advisory ↗
Red HatCVE-2026-28907CVSS 6.5Red Hat Enterprise Linux AppStream EUS (v.9.6)webkit2gtk3-0:2.52.4-1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-28958CVSS 6.5Red Hat Enterprise Linux AppStream EUS (v.9.6)webkit2gtk3-0:2.52.4-1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9Red Hat Enterprise Linux AppStream (v. 9)buildah-2:1.43.1-2.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9Red Hat Enterprise Linux AppStream (v. 9)runc-4:1.4.2-2.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9Red Hat Enterprise Linux AppStream (v. 9)containernetworking-plugins-1:1.9.0-3.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9OpenShift API for Data Protection 1.4registry.redhat.io/oadp/oadp-kubevirt-velero-plugin-rhel9@sha256:17af493f7fee34d568b9d5619adfd7e087c28a8038e511d254a3999c37c58ef8_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33748CVSS 6.5OpenShift API for Data Protection 1.4registry.redhat.io/oadp/oadp-mustgather-rhel9@sha256:4490beeb9fdb719cc93232301a83637a1b0ce702bee0fd910ccd3cd4c11e50d0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-3833CVSS 6.5Red Hat Enterprise Linux AppStream EUS (v.9.6)gnutls-c++-0:3.8.3-6.el9_6.4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-40612CVSS 5.5Red Hat Hardened Imagesjq-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-41256CVSS 5.5Red Hat Hardened Imagesjq-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-41257CVSS 5.5Red Hat Hardened Imagesjq-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-42014CVSS 6.6Red Hat Enterprise Linux AppStream EUS (v.9.6)gnutls-c++-0:3.8.3-6.el9_6.4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-42015CVSS 5.3Red Hat Enterprise Linux AppStream EUS (v.9.6)gnutls-c++-0:3.8.3-6.el9_6.4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-42507CVSS 5.3Red Hat Enterprise Linux AppStream (v. 10)go-toolset-0:1.26.4-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-42507CVSS 5.3Red Hat Enterprise Linux AppStream (v. 9)go-toolset-0:1.26.4-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-43660CVSS 6.5Red Hat Enterprise Linux AppStream EUS (v.9.6)webkit2gtk3-0:2.52.4-1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-43894CVSS 6.2Red Hat Hardened Imagesjq-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-43895CVSS 4.4Red Hat Hardened Imagesjq-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-43896CVSS 5.5Red Hat Hardened Imagesjq-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-44431CVSS 5.9Red Hat AI Inference Server 3.3registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:21867e83ef2af0458c1eff854005781fbb527370bca8a1e90b404b5119ad2478_amd64Patch ↗Advisory ↗

Glossary