CYBERSECURITYTRACKER
TRACKING7,931 stories in this site build1,728 vulnerability news stories in this site build
Vulnerabilities

June 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 0 vulnerabilities with exploitation detected in the wild this month. This defender-focused view covers 2,852 vulnerabilities across 11,856 returned patch records from 5 vendors. Filter the complete month, or browse the static page trail without JavaScript.

11,856all patch recordsClear filters873criticalShow these records0Microsoft exploitation detectedShow these records2Microsoft in the Known Exploited Vulnerabilities catalogShow these records10,017tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

My Stack only keeps records whose vendor you have pinned. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 52 of 60 · records 10,201 to 10,400 of 11,856

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-58058 ↗azl3 nmap 7.95-4 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableNmap - Integer Underflow in IPv6 Extension Header Parsing
CVE-2026-58055 ↗azl3 fluent-bit 3.1.10-6 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length
CVE-2026-53655 ↗azl3 tar 1.35-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenode-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)
CVE-2026-44889 ↗azl3 python-webob 1.8.8-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableWebOb: Location header normalization during redirect leads to open redirect
CVE-2026-53279 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/gma500/oaktrail_lvds: fix hang on init failure
CVE-2026-53295 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemailbox: add sanity check for channel array
CVE-2026-53314 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepadata: Put CPU offline callback in ONLINE section to allow failure
CVE-2026-53291 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALSA: hda/conexant: Fix missing error check for jack detection
CVE-2026-53287 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableaudit: fix incorrect inheritable capability in CAPSET records
CVE-2026-53289 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableice: fix NULL pointer dereference in ice_reset_all_vfs()
CVE-2026-53293 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG
CVE-2026-53297 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: mana: Guard mana_remove against double invocation
CVE-2026-53313 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths
CVE-2026-53292 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind
CVE-2026-53304 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablescsi: sg: Resolve soft lockup issue when opening /dev/sgX
CVE-2026-53320 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty()
CVE-2026-53252 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: fix memory leak in error path of hci_alloc_dev()
CVE-2026-53263 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailable6lowpan: fix off-by-one in multicast context address compression
CVE-2026-53154 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemm/hugetlb: restore reservation on error in hugetlb folio copy paths
CVE-2026-57454 ↗azl3 vim 9.2.0488-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVim: Out-of-bounds Read with Text Properties
CVE-2026-57453 ↗azl3 vim 9.2.0620-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction
CVE-2026-57451 ↗azl3 vim 9.2.0620-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVim: Out-of-bounds Read in Text Property Count
CVE-2026-52941 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint
CVE-2026-55892 ↗azl3 vim 9.2.0488-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVim: Out-of-bounds Write in Spell File Prefix Dump
CVE-2026-55693 ↗azl3 vim 9.2.0620-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVim: Out-of-bounds Write in Spell File Word Count
CVE-2026-55895 ↗azl3 vim 9.2.0488-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename
CVE-2026-57455 ↗azl3 vim 9.2.0488-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argument
CVE-2026-52984 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/sched: netem: fix queue limit check to include reordered packets
CVE-2026-57452 ↗azl3 vim 9.2.0488-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableVim: Out-of-bounds Read with libsodium-encrypted Files
CVE-2026-52985 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetdevsim: zero initialize struct iphdr in dummy sk_buff
CVE-2026-53034 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf, sockmap: Fix af_unix null-ptr-deref in proto update
CVE-2026-53102 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req()
CVE-2026-53056 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/msm/dpu: fix mismatch between power and frequency
CVE-2026-53058 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in atomic_enable()
CVE-2026-53108 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablepowerpc/64s: Fix unmap race with PMD migration entries
CVE-2026-53080 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/sched: cls_fw: fix NULL dereference of "old" filters before change()
CVE-2026-53219 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: x_tables: avoid leaking percpu counter pointers
CVE-2026-53135 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs
CVE-2026-57436 ↗azl3 rubygem-nokogiri 1.15.4-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableNokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type
CVE-2026-57437 ↗azl3 rubygem-nokogiri 1.15.4-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableNokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime
CVE-2026-53074 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb
CVE-2026-52930 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableipc/shm: serialize orphan cleanup with shm_nattch updates
CVE-2026-57438 ↗azl3 rubygem-nokogiri 1.15.4-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableNokogiri: Possible Use-After-Free in XInclude Processing
CVE-2026-52928 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableaf_unix: Reject SIOCATMARK on non-stream sockets
CVE-2026-53167 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios
CVE-2026-52964 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans
CVE-2026-53106 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Do not allow deleting local storage in NMI
CVE-2026-53111 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap
CVE-2026-52970 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nft_ct: fix missing expect put in obj eval
CVE-2026-53226 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablegpio: rockchip: fix generic IRQ chip leak on remove
CVE-2026-53048 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablegfs2: prevent NULL pointer dereference during unmount
CVE-2026-53128 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrbd: Balance RCU calls in drbd_adm_dump_devices()
CVE-2026-53037 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableHID: usbhid: fix deadlock in hid_post_reset()
CVE-2026-52925 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevrf: Fix a potential NPD when removing a port from a VRF
CVE-2026-53208 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig
CVE-2026-53066 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/sun4i: backend: fix error pointer dereference
CVE-2026-53064 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledm cache: fix null-deref with concurrent writes in passthrough mode
CVE-2026-53258 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: fix leak if split 6 GHz scanning fails
CVE-2026-53047 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableefi/capsule-loader: fix incorrect sizeof in phys array reallocation
CVE-2026-53220 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: revalidate bridge ports
CVE-2026-52937 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR
CVE-2026-52977 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefutex: Prevent lockup in requeue-PI during signal/ timeout wakeup
CVE-2026-53190 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait()
CVE-2026-53245 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr
CVE-2026-53061 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledm cache: fix dirty mapping checking in passthrough mode switching
CVE-2026-52961 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size
CVE-2026-53107 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: libertas: don't kill URBs in interrupt context
CVE-2026-53122 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebtrfs: fix deadlock between reflink and transaction commit when using flushoncommit
CVE-2026-53168 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefuse: reject fuse_notify() pagecache ops on directories
CVE-2026-52963 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableALSA: usb-audio: Bound MIDI endpoint descriptor scans
CVE-2026-53214 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableipv6: Fix a potential NPD in cleanup_prefix_route()
CVE-2026-53035 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf, sockmap: Fix af_unix iter deadlock
CVE-2026-52936 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablecrypto: jitterentropy - replace long-held spinlock with mutex
CVE-2026-53237 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablegpio: mvebu: fix NULL pointer dereference in suspend/resume
CVE-2026-53073 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error
CVE-2026-53113 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: ath11k: fix memory leaks in beacon template setup
CVE-2026-53218 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nft_exthdr: fix register tracking for F_PRESENT flag
CVE-2026-53166 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablefutex/requeue: Prevent NULL pointer dereference in remove_waiter() on self-deadlock
CVE-2026-53032 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebpf: Fix NULL deref in map_kptr_match_type for scalar regs
CVE-2026-53093 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewifi: brcmfmac: Fix error pointer dereference
CVE-2026-53015 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableerofs: unify lcn as u64 for 32-bit platforms
CVE-2026-53082 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: hamradio: 6pack: fix uninit-value in sixpack_receive_buf
CVE-2026-52996 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableksmbd: fix durable fd leak on ClientGUID mismatch in durable v2 open
CVE-2026-53063 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledm cache: fix write hang in passthrough mode
CVE-2026-53060 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledm cache metadata: fix memory leak on metadata abort retry
CVE-2026-53139 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/v3d: Skip CSD when it has zeroed workgroups
CVE-2026-53249 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableipv4: restrict IPOPT_SSRR and IPOPT_LSRR options
CVE-2026-53177 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebnxt_en: Fix NULL pointer dereference
CVE-2026-53158 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemisc: fastrpc: Fix NULL pointer dereference in rpmsg callback
CVE-2026-53181 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablevsock/vmci: fix sk_ack_backlog leak on failed handshake
CVE-2026-47242 ↗azl3 ruby 3.3.5-8 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableNet::IMAP: Command Injection via ID command argument
CVE-2026-47240 ↗azl3 ruby 3.3.5-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableNet::IMAP: Command Injection via non-synchronizing literal in "raw" argument
CVE-2026-53163 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelocking/rtmutex: Skip remove_waiter() when waiter is not enqueued
CVE-2026-53022 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableplatform/x86: dell-wmi-sysman: bound enumeration string aggregation
CVE-2026-53150 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablethunderbolt: Reject zero-length property entries in validator
CVE-2026-53013 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablemacvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF
CVE-2026-3196 ↗azl3 qemu 9.1.0-8 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableQemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation
CVE-2026-52916 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablebatman-adv: frag: disallow unicast fragment in fragment
CVE-2026-0864 ↗azl3 python3 3.12.9-11 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableConfiguration Injection via Carriage Return (\r) in write() method
CVE-2026-9539 ↗azl3 libslirp 4.7.0-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibslirp TCP URG OOB Read Information Leak
CVE-2026-53126 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableblk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current()
CVE-2026-47770 ↗azl3 jq 1.7.1-6 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablejq: stack overflow in deep structural equality
CVE-2026-53065 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableASoC: sti: use managed regmap_field allocations
CVE-2026-54679 ↗azl3 jq 1.7.1-6 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablejq: potential integer overflow in jvp_string_append
CVE-2026-53274 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS
CVE-2026-56131 ↗azl3 cmake 3.30.3-13 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
CVE-2026-56412 ↗azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablelibexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.
CVE-2026-56410 ↗azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablexmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
CVE-2026-53236 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabletcp: restrict SO_ATTACH_FILTER to priv users
CVE-2026-56409 ↗azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablexmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
CVE-2026-53012 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenexthop: fix IPv6 route referencing IPv4 nexthop
CVE-2026-56411 ↗azl3 expat 2.6.4-6 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablexmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
CVE-2026-53238 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetlabel: validate unlabeled address and mask attribute lengths
CVE-2026-56132 ↗azl3 cmake 3.30.3-13 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableIn libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.
CVE-2026-55653 ↗azl3 openssh 9.8p1-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableOpenssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-42245CVSS 6.5Red Hat Enterprise Linux AppStream (v. 9)ruby-0:4.0.3-33.module+el9.8.0+24428+77f1d00a.aarch64::ruby:4.0Patch ↗Advisory ↗
Red HatCVE-2026-42245CVSS 6.5Red Hat Hardened Imagesruby3-3-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-42256CVSS 6.5Red Hat Hardened Imagesruby4-0-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-42256CVSS 6.5Red Hat Hardened Imagesruby3-4-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-42256CVSS 6.5Red Hat Hardened Imagesruby3-3-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-42507CVSS 5.3Red Hat OpenShift distributed tracing 3.10.2registry.redhat.io/rhosdt/tempo-gateway-opa-rhel9@sha256:1c35ffcda8a79fde89e015fff93a8ac141f8dba83005544e84720b798238f199_amd64Patch ↗Advisory ↗
Red HatCVE-2026-44169CVSS 4.3Red Hat Enterprise Linux AppStream (v. 10)mariadb11.8-3:11.8.8-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-44169CVSS 4.3Red Hat Enterprise Linux AppStream (v. 9)galera-0:26.4.27-1.module+el9.8.0+24389+c97c30be.aarch64::mariadb:11.8Patch ↗Advisory ↗
Red HatCVE-2026-44171CVSS 5.8Red Hat Enterprise Linux AppStream (v. 10)mariadb11.8-3:11.8.8-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-44171CVSS 5.8Red Hat Enterprise Linux AppStream (v. 8)Judy-0:1.0.5-18.module+el8.10.0+21221+7bee72c1.aarch64::mariadb:10.11Patch ↗Advisory ↗
Red HatCVE-2026-44171CVSS 5.8Red Hat Enterprise Linux AppStream (v. 9)galera-0:26.4.27-1.module+el9.8.0+24389+c97c30be.aarch64::mariadb:11.8Patch ↗Advisory ↗
Red HatCVE-2026-44171CVSS 5.8Red Hat Enterprise Linux AppStream (v. 9)galera-0:26.4.27-1.module+el9.8.0+24388+85f1c439.aarch64::mariadb:10.11Patch ↗Advisory ↗
Red HatCVE-2026-44605CVSS 5.5Red Hat Hardened Imagesrpm-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4647CVSS 6.1Red Hat Hardened Imagesbinutils-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47240CVSS 6.1Red Hat Hardened Imagesruby4-0-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47241CVSS 5.9Red Hat Hardened Imagesruby4-0-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-48619CVSS 5.3Red Hat Hardened Imagesnodejs26-0:26.4.0-1.3.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-48928CVSS 4.2Red Hat Hardened Imagesnodejs26-0:26.4.0-1.3.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-48930CVSS 5.6Red Hat Hardened Imagesnodejs26-0:26.4.0-1.3.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-48934CVSS 4.3Red Hat Hardened Imagesnodejs26-0:26.4.0-1.3.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-53550CVSS 5.3Red Hat Hardened Imagesnodejs26-0:26.4.0-1.3.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6019CVSS 6.8Red Hat Hardened Imagespython3-11-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6472CVSS 5.4Red Hat Enterprise Linux AppStream E4S (v.9.4)pg_repack-0:1.4.8-1.module+el9.2.0+17405+aeb9ec60.aarch64::postgresql:15Patch ↗Advisory ↗
Red HatCVE-2026-6472CVSS 5.4Red Hat Enterprise Linux AppStream E4S (v.9.2)pg_repack-0:1.4.8-1.module+el9.2.0+17405+aeb9ec60.aarch64::postgresql:15Patch ↗Advisory ↗
Red HatCVE-2026-6474CVSS 4.3Red Hat Enterprise Linux AppStream E4S (v.9.4)pg_repack-0:1.4.8-1.module+el9.2.0+17405+aeb9ec60.aarch64::postgresql:15Patch ↗Advisory ↗
Red HatCVE-2026-6474CVSS 4.3Red Hat Enterprise Linux AppStream E4S (v.9.2)pg_repack-0:1.4.8-1.module+el9.2.0+17405+aeb9ec60.aarch64::postgresql:15Patch ↗Advisory ↗
Red HatCVE-2026-6735CVSS 5.4Red Hat Enterprise Linux AppStream (v. 9)php-0:8.0.30-6.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-7258CVSS 5.9Red Hat Enterprise Linux AppStream (v. 9)php-0:8.0.30-6.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-7259CVSS 6.5Red Hat Enterprise Linux AppStream (v. 9)php-0:8.0.30-6.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-7261CVSS 5.6Red Hat Enterprise Linux AppStream (v. 9)php-0:8.0.30-6.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-8723CVSS 5.3Red Hat Hardened Imagespython3-14-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-9673CVSS 6.1Red Hat Developer Hub 1.9registry.redhat.io/rhdh/rhdh-hub-rhel9@sha256:044d2d72c21329826c144d9b55c381576a421188139de0fed693e74997665d2c_amd64Patch ↗Advisory ↗
Red HatCVE-2024-12133CVSS 5.3Red Hat Enterprise Linux AppStream AUS (v.8.6)gnutls-c++-0:3.6.16-5.el8_6.5.i686Patch ↗Advisory ↗
Red HatCVE-2024-12133CVSS 5.3Red Hat Enterprise Linux AppStream E4S (v.8.8)gnutls-c++-0:3.6.16-7.el8_8.4.i686Patch ↗Advisory ↗
Red HatCVE-2024-12133CVSS 5.3Red Hat Enterprise Linux AppStream AUS (v.8.4)gnutls-c++-0:3.6.14-10.el8_4.1.i686Patch ↗Advisory ↗
Red HatCVE-2024-34459CVSS 5.5Red Hat Discovery 2registry.redhat.io/discovery/discovery-server-rhel9@sha256:6c26d60b5d8eb5a823be4d6e83f2ebb32f5d15216338b85eb4b08aca4dc9316d_arm64Patch ↗Advisory ↗
Red HatCVE-2024-55565CVSS 6.5Red Hat Ceph Storage 7.1registry.redhat.io/rhceph/rhceph-7-rhel9@sha256:57eaf98ed402584fca1e6b804ad97fbf2287219ad617f69c96b0cd48279e7a98_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-10911CVSS 5.5Red Hat Enterprise Linux AppStream AUS (v.8.6)libxslt-debuginfo-0:1.1.32-8.el8_6.1.i686Patch ↗Advisory ↗
Red HatCVE-2025-10911CVSS 5.5Red Hat Discovery 2registry.redhat.io/discovery/discovery-ui-rhel9@sha256:3152cbb7f8ab85315ebb95b9f5cd5793c40859ee4487587f16a525ac5d408a44_arm64Patch ↗Advisory ↗
Red HatCVE-2025-14831CVSS 5.3Red Hat Enterprise Linux AppStream AUS (v.8.6)gnutls-c++-0:3.6.16-5.el8_6.5.i686Patch ↗Advisory ↗
Red HatCVE-2025-14831CVSS 5.3Red Hat Enterprise Linux AppStream E4S (v.8.8)gnutls-c++-0:3.6.16-7.el8_8.4.i686Patch ↗Advisory ↗
Red HatCVE-2025-14831CVSS 5.3Red Hat Enterprise Linux AppStream AUS (v.8.4)gnutls-c++-0:3.6.14-10.el8_4.1.i686Patch ↗Advisory ↗
Red HatCVE-2025-50181CVSS 5.3Red Hat Ceph Storage 7.1registry.redhat.io/rhceph/grafana-rhel9@sha256:8bcb8976618246bc3c73f7986b7d566d9d26cda16c6043f6820f6efa2f8a3c2c_amd64Patch ↗Advisory ↗
Red HatCVE-2025-52555CVSS 6.5Red Hat Ceph Storage 7.1registry.redhat.io/rhceph/rhceph-7-rhel9@sha256:57eaf98ed402584fca1e6b804ad97fbf2287219ad617f69c96b0cd48279e7a98_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-5278CVSS 4.4Red Hat Enterprise Linux BaseOS (v. 10)coreutils-0:9.5-8.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-5278CVSS 4.4Red Hat Discovery 2registry.redhat.io/discovery/discovery-ui-rhel9@sha256:3152cbb7f8ab85315ebb95b9f5cd5793c40859ee4487587f16a525ac5d408a44_arm64Patch ↗Advisory ↗
Red HatCVE-2026-12302CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.12.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12306CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.12.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12307CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.12.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12308CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.12.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12309CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.12.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12311CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.12.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12313CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.12.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-12330CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.12.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-34079CVSS 6.7Red Hat Enterprise Linux AppStream AUS (v.8.4)flatpak-0:1.12.9-2.el8_4.srcPatch ↗Advisory ↗
Red HatCVE-2026-35177CVSS 4.1Red Hat Enterprise Linux AppStream EUS (v. 10.0)vim-X11-2:9.1.083-5.el10_0.3.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-3833CVSS 6.5Red Hat Enterprise Linux AppStream AUS (v.8.6)gnutls-c++-0:3.6.16-5.el8_6.5.i686Patch ↗Advisory ↗
Red HatCVE-2026-3833CVSS 6.5Red Hat Enterprise Linux AppStream E4S (v.8.8)gnutls-c++-0:3.6.16-7.el8_8.4.i686Patch ↗Advisory ↗
Red HatCVE-2026-3833CVSS 6.5Red Hat Enterprise Linux AppStream E4S (v.9.4)gnutls-c++-0:3.8.3-4.el9_4.6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-3833CVSS 6.5Red Hat Enterprise Linux AppStream AUS (v.8.4)gnutls-c++-0:3.6.14-10.el8_4.1.i686Patch ↗Advisory ↗
Red HatCVE-2026-42014CVSS 6.6Red Hat Enterprise Linux AppStream AUS (v.8.6)gnutls-c++-0:3.6.16-5.el8_6.5.i686Patch ↗Advisory ↗
Red HatCVE-2026-42014CVSS 6.6Red Hat Enterprise Linux AppStream E4S (v.8.8)gnutls-c++-0:3.6.16-7.el8_8.4.i686Patch ↗Advisory ↗
Red HatCVE-2026-42014CVSS 6.6Red Hat Enterprise Linux AppStream E4S (v.9.4)gnutls-c++-0:3.8.3-4.el9_4.6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-42014CVSS 6.6Red Hat Enterprise Linux AppStream AUS (v.8.4)gnutls-c++-0:3.6.14-10.el8_4.1.i686Patch ↗Advisory ↗
Red HatCVE-2026-42015CVSS 5.3Red Hat Enterprise Linux AppStream AUS (v.8.6)gnutls-c++-0:3.6.16-5.el8_6.5.i686Patch ↗Advisory ↗
Red HatCVE-2026-42015CVSS 5.3Red Hat Enterprise Linux AppStream E4S (v.8.8)gnutls-c++-0:3.6.16-7.el8_8.4.i686Patch ↗Advisory ↗
Red HatCVE-2026-42015CVSS 5.3Red Hat Enterprise Linux AppStream E4S (v.9.4)gnutls-c++-0:3.8.3-4.el9_4.6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-42015CVSS 5.3Red Hat Enterprise Linux AppStream AUS (v.8.4)gnutls-c++-0:3.6.14-10.el8_4.1.i686Patch ↗Advisory ↗
Red HatCVE-2026-44171CVSS 5.8Red Hat Enterprise Linux AppStream (v. 10)mariadb-3:10.11.18-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-46692CVSS 5.9Red Hat Enterprise Linux Server (v. 7 ELS)ImageMagick-0:6.9.10.68-17.el7_9.i686Patch ↗Advisory ↗
Red HatCVE-2026-47262CVSS 6.5Red Hat Hardened Imagesgrype-0:0.115.0-0.1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47262CVSS 6.5Red Hat Hardened Imagessyft-0:1.46.0-0.1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-50229CVSS 5.4Red Hat Hardened Imagestomcat11-0:11.0.23-0.1.hum1@noarchPatch ↗Advisory ↗
Red HatCVE-2026-55955CVSS 4.2Red Hat Hardened Imagestomcat11-0:11.0.23-0.1.hum1@noarchPatch ↗Advisory ↗
Red HatCVE-2026-55956CVSS 6.5Red Hat Hardened Imagestomcat11-0:11.0.23-0.1.hum1@noarchPatch ↗Advisory ↗
Red HatCVE-2026-6019CVSS 6.8Red Hat Hardened Imagespython3-12-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6019CVSS 6.8Red Hat Hardened Imagespython3-13-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6472CVSS 5.4Red Hat Enterprise Linux AppStream EUS (v.9.6)pg_repack-0:1.4.8-2.module+el9.5.0+22224+f5585c78.aarch64::postgresql:15Patch ↗Advisory ↗
Red HatCVE-2026-6474CVSS 4.3Red Hat Enterprise Linux AppStream EUS (v.9.6)pg_repack-0:1.4.8-2.module+el9.5.0+22224+f5585c78.aarch64::postgresql:15Patch ↗Advisory ↗
Red HatCVE-2025-47914CVSS 5.3multicluster engine for Kubernetes 2.8registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:13c3febd4002fec374561ab0e3b00280c08341d70a239f5af7ade36233b79759_arm64Patch ↗Advisory ↗
Red HatCVE-2026-35206CVSS 4.4multicluster engine for Kubernetes 2.8registry.redhat.io/multicluster-engine/backplane-rhel9-operator@sha256:13c3febd4002fec374561ab0e3b00280c08341d70a239f5af7ade36233b79759_arm64Patch ↗Advisory ↗
Red HatCVE-2026-35206CVSS 4.4Red Hat Advanced Cluster Management for Kubernetes 2.13registry.redhat.io/rhacm2/multicloud-integrations-rhel9@sha256:188aa1452e1727a3722729d73c560969cd02bfa29601eba3bca65945027c5fbf_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-50219CVSS 4.9Red Hat Hardened Imagesexpat-0:2.8.2-1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-56132CVSS 6.9Red Hat Hardened Imagesexpat-0:2.8.2-1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-9150CVSS 6.5Red Hat Hardened Imageslibsolv-main@aarch64Patch ↗Advisory ↗

Glossary