CYBERSECURITYTRACKER
TRACKING7,183 stories in this site build1,510 vulnerability news stories in this site build
Vulnerabilities

July 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 3 vulnerabilities with exploitation detected in the wild this month. This defender-focused view covers 3,179 vulnerabilities across 7,361 returned patch records from 3 vendors. Filter the complete month, or browse the static page trail without JavaScript.

7,361all patch recordsClear filters210criticalShow these records3Microsoft exploitation detectedShow these records6Microsoft in the Known Exploited Vulnerabilities catalogShow these records2,256tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 1 of 37 · records 1 to 200 of 7,361

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-58644 ↗Microsoft SharePoint Enterprise Server 2016Critical16%Microsoft rates: Exploitation DetectedCISA KEVVulnCheckENISAKB5002873KB5002874
and 1 moreKB5002880
6 mentionsMicrosoft SharePoint Remote Code Execution Vulnerability
CVE-2026-56155 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation DetectedCISA KEVVulnCheckENISAKB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
6 mentionsActive Directory Federation Services Elevation of Privilege Vulnerability
CVE-2026-56164 ↗Microsoft SharePoint Enterprise Server 2016Moderate27%Microsoft rates: Exploitation DetectedCISA KEVVulnCheckENISAKB5002882KB5002883
and 1 moreKB5002891
9 mentionsMicrosoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2026-50522 ↗Microsoft SharePoint Enterprise Server 2016Critical85%Microsoft rates: Exploitation More LikelyCISA KEVVulnCheckENISAKB5002882KB5002883
and 1 moreKB5002891
6 mentionsMicrosoft SharePoint Remote Code Execution Vulnerability
CVE-2026-55040 ↗Microsoft SharePoint Enterprise Server 2016Critical51%Microsoft rates: Exploitation More LikelyCISA KEVVulnCheckENISAKB5002882KB5002883
and 1 moreKB5002891
8 mentionsMicrosoft SharePoint Server Security Feature Bypass Vulnerability
CVE-2026-53362 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableCISA KEVVulnCheckENISA1 mentionsipv6: account for fraggap on the paged allocation path
CVE-2026-11564 ↗azl3 rust 1.75.0-30 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailableNative CA trust persist
CVE-2026-48144 ↗azl3 thrift 0.15.0-6 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailableApache Thrift: c_glib TLS Client Missing Hostname Verification
CVE-2026-66803 ↗Azure Cosmos DBCriticalOut-of-band1%Microsoft rates: Exploitation Less LikelyAzure Cosmos DB Remote Code Execution Vulnerability
CVE-2026-64319 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band1%Microsoft rating unavailablenvmet-auth: validate reply message payload bounds against transfer length
CVE-2026-35425 ↗Azure API Management (APIM)CriticalOut-of-band1%Microsoft rates: N/AAzure API Management (APIM) Remote Code Execution Vulnerability
CVE-2026-49159 ↗Microsoft GraphCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Graph Information Disclosure Vulnerability
CVE-2026-50517 ↗Microsoft 365 CopilotCriticalOut-of-band1%Microsoft rates: N/AMicrosoft M365 Copilot Remote Code Execution Vulnerability
CVE-2026-54120 ↗Surface Management ServicesCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Surface Remote Code Execution Vulnerability
CVE-2026-56160 ↗Azure Red Hat OpenShift (ARO)CriticalOut-of-band1%Microsoft rates: N/AAzure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability
CVE-2026-56163 ↗Azure Kubernetes ServiceCriticalOut-of-band0%Microsoft rates: N/AMicrosoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CVE-2026-56165 ↗Microsoft AccountCriticalOut-of-band1%Microsoft rates: Exploitation Less LikelyMicrosoft Account Remote Code Execution Vulnerability
CVE-2026-56167 ↗Azure AI SearchCriticalOut-of-band0%Microsoft rates: N/AAzure AI Search Elevation of Privilege Vulnerability
CVE-2026-56191 ↗Microsoft Exchange OnlineCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Exchange Online Tampering Vulnerability
CVE-2026-57106 ↗Microsoft Purview Data GovernanceCriticalOut-of-band0%Microsoft rates: N/AData Quality Elevation of Privilege Vulnerability
CVE-2026-58275 ↗Azure DNSCriticalOut-of-band1%Microsoft rates: N/AAzure DNS Elevation of Privilege Vulnerability
CVE-2026-58630 ↗Azure App Service for LinuxCriticalOut-of-band0%Microsoft rates: N/AAzure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
CVE-2026-62825 ↗Azure Key VaultCriticalOut-of-band1%Microsoft rates: N/AAzure Key Vault Elevation of Privilege Vulnerability
CVE-2026-62835 ↗Azure PortalCriticalOut-of-band1%Microsoft rates: N/AAzure Portal Information Disclosure Vulnerability
CVE-2026-63979 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band1%Microsoft rating unavailablenet/handshake: hand off the pinned file reference to accept_doit
CVE-2026-64138 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailableksmbd: validate SID in parent security descriptor during ACL inheritance
CVE-2026-42533 ↗azl3 nginx 1.28.3-6 on Azure Linux 3.0CriticalOut-of-band4%Microsoft rating unavailable1 mentionsNGINX Map directive and Regex matching vulnerability
CVE-2026-57433 ↗azl3 perl 5.38.2-512 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailableStorable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record
CVE-2026-42982 ↗Windows 10 Version 1809 for 32-bit SystemsCritical0%Microsoft rates: Exploitation Less LikelyKB5095051KB5099414
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
CVE-2026-48561 ↗Microsoft Edge Copilot for AndroidCritical1%Microsoft rates: Exploitation Less Likely1 mentionsMicrosoft Edge Copilot Remote Code Execution Vulnerability
CVE-2026-48564 ↗Windows 10 Version 1809 for 32-bit SystemsCritical1%Microsoft rates: Exploitation Less LikelyKB5094041KB5094042
and 4 moreKB5099535KB5099536KB5099538KB5099540
1 mentionsDHCP Server Service Remote Code Execution Vulnerability
CVE-2026-49164 ↗Windows 10 Version 1809 for 32-bit SystemsCritical1%Microsoft rates: Exploitation UnlikelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Active Directory Domain Services Remote Code Execution Vulnerability
CVE-2026-49796 ↗Windows 10 Version 1809 for 32-bit SystemsCritical0%Microsoft rates: Exploitation Less LikelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsWindows GDI+ Remote Code Execution Vulnerability
CVE-2026-50314 ↗Microsoft Office 365 for MacCritical0%Microsoft rates: Exploitation Less LikelyKB50028871 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-50327 ↗Windows Server 2025 (Server Core installation)Critical0%Microsoft rates: Exploitation More LikelyKB5099536KB5101649
and 1 moreKB5101650
1 mentionsWindows Media Remote Code Execution Vulnerability
CVE-2026-50370 ↗Windows 10 Version 1809 for 32-bit SystemsCritical1%Microsoft rates: Exploitation More LikelyKB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
1 mentionsDHCP Server Service Remote Code Execution Vulnerability
CVE-2026-50380 ↗Windows 10 Version 1809 for 32-bit SystemsCritical1%Microsoft rates: Exploitation Less LikelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsWindows GDI+ Remote Code Execution Vulnerability
CVE-2026-50382 ↗Windows 10 Version 1809 for 32-bit SystemsCritical0%Microsoft rates: Exploitation Less LikelyKB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
1 mentionsDirectX Graphics Kernel Remote Code Execution Vulnerability
CVE-2026-50392 ↗Windows 11 Version 25H2 for x64-based SystemsCritical0%Microsoft rates: Exploitation Less LikelyKB5099536KB5101649
and 1 moreKB5101650
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
CVE-2026-50444 ↗Windows 10 Version 1809 for 32-bit SystemsCritical1%Microsoft rates: Exploitation Less LikelyKB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
CVE-2026-50467 ↗Microsoft Office 2019 for 32-bit editionsCritical0%Microsoft rates: Exploitation Less LikelyKB50028871 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-50474 ↗Windows 10 Version 1809 for 32-bit SystemsCritical1%Microsoft rates: Exploitation UnlikelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsRemote Desktop Client Remote Code Execution Vulnerability
CVE-2026-50518 ↗Windows 10 Version 1809 for 32-bit SystemsCritical1%Microsoft rates: Exploitation More LikelyKB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
1 mentionsWindows DHCP Server Remote Code Execution Vulnerability
CVE-2026-50655 ↗Windows 10 Version 1809 for 32-bit SystemsCritical0%Microsoft rates: Exploitation More LikelyKB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsMicrosoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2026-50680 ↗Windows 10 Version 1809 for 32-bit SystemsCritical0%Microsoft rates: Exploitation Less LikelyKB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2026-50694 ↗Windows 10 Version 1809 for 32-bit SystemsCritical1%Microsoft rates: Exploitation UnlikelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2026-54117 ↗Microsoft SQL Server 2025 for x64-based Systems (GDR)Critical1%Microsoft rates: Exploitation Less LikelyKB5101346KB5102333Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-54118 ↗Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature PackCritical1%Microsoft rates: Exploitation Less LikelyKB5101346KB5101347
and 8 moreKB5102333KB5102334KB5102335KB5102336KB5102337KB5102338KB5102339KB5102340
Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-54121 ↗Windows 10 Version 1809 for 32-bit SystemsCritical2%Microsoft rates: Exploitation Less LikelyKB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
2 mentionsActive Directory Certificate Services Elevation of Privilege Vulnerability
CVE-2026-54127 ↗Windows Server 2022Critical0%Microsoft rates: Exploitation Less LikelyKB5099536KB5099540
and 2 moreKB5101649KB5101650
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2026-54128 ↗Windows 10 Version 1809 for 32-bit SystemsCritical0%Microsoft rates: Exploitation More LikelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsWindows DHCP Client Remote Code Execution Vulnerability
CVE-2026-54982 ↗Windows 10 Version 1809 for 32-bit SystemsCritical1%Microsoft rates: Exploitation Less LikelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsWindows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2026-54992 ↗Windows 10 Version 1809 for 32-bit SystemsCritical0%Microsoft rates: Exploitation More LikelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsMicrosoft Message Queuing Queue Manager Remote Code Execution Vulnerability
CVE-2026-54995 ↗Windows 10 Version 1809 for 32-bit SystemsCritical1%Microsoft rates: Exploitation UnlikelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsWindows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2026-54999 ↗Windows 10 Version 1809 for 32-bit SystemsCritical0%Microsoft rates: Exploitation Less LikelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows TCP/IP Remote Code Execution Vulnerability
CVE-2026-55008 ↗Microsoft Exchange Server 2016 Cumulative Update 23Critical1%Microsoft rates: Exploitation More LikelyKB5103212KB5103213
and 2 moreKB5103214KB5103215
Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-55010 ↗Minecraft Bedrock Dedicated ServerCritical1%Microsoft rates: Exploitation More Likely1 mentionsMinecraft Bedrock Dedicated Server Remote Code Execution Vulnerability
CVE-2026-55011 ↗Microsoft Malware Protection EngineCritical0%Microsoft rates: Exploitation Less LikelyMicrosoft Defender Remote Code Execution Vulnerability
CVE-2026-55012 ↗Microsoft Malware Protection EngineCritical0%Microsoft rates: Exploitation Less LikelyMicrosoft Defender Remote Code Execution Vulnerability
CVE-2026-55018 ↗Microsoft Office 365 for MacCritical0%Microsoft rates: Exploitation Less LikelyKB50028871 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55022 ↗Microsoft Office 365 for MacCritical0%Microsoft rates: Exploitation Less LikelyKB50028871 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55033 ↗Microsoft SharePoint Server 2019Critical1%Microsoft rates: Exploitation Less LikelyKB5002882KB5002883
and 4 moreKB5002885KB5002890KB5002891KB5002892
1 mentionsMicrosoft Word Remote Code Execution Vulnerability
CVE-2026-55043 ↗Microsoft Office 365 for MacCritical0%Microsoft rates: Exploitation Less LikelyKB50028671 mentionsMicrosoft PowerPoint Remote Code Execution Vulnerability
CVE-2026-55045 ↗Microsoft SharePoint Enterprise Server 2016Critical0%Microsoft rates: Exploitation Less LikelyKB5002882KB5002883
and 4 moreKB5002885KB5002887KB5002891KB5002892
1 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55049 ↗Microsoft Office 2019 for 32-bit editionsCritical0%Microsoft rates: Exploitation Less LikelyKB50027481 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55056 ↗Microsoft Office 2019 for 32-bit editionsCritical0%Microsoft rates: Exploitation Less LikelyKB50028871 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55120 ↗Microsoft Office 2019 for 32-bit editionsCritical0%Microsoft rates: Exploitation Less LikelyKB50028671 mentionsMicrosoft PowerPoint Remote Code Execution Vulnerability
CVE-2026-55123 ↗Microsoft Office 365 for MacCritical0%Microsoft rates: Exploitation Less LikelyKB50028671 mentionsMicrosoft PowerPoint Remote Code Execution Vulnerability
CVE-2026-55127 ↗Microsoft SharePoint Server 2019Critical1%Microsoft rates: Exploitation Less LikelyKB5002882KB5002883
and 4 moreKB5002885KB5002890KB5002891KB5002892
1 mentionsMicrosoft Word Remote Code Execution Vulnerability
CVE-2026-55129 ↗Microsoft Office 2019 for 32-bit editionsCritical0%Microsoft rates: Exploitation Less LikelyKB50028871 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55132 ↗Microsoft Office 365 for MacCritical1%Microsoft rates: Exploitation Less LikelyKB5002882KB5002883
and 4 moreKB5002885KB5002890KB5002891KB5002892
1 mentionsMicrosoft Word Remote Code Execution Vulnerability
CVE-2026-55140 ↗Microsoft Office 365 for MacCritical0%Microsoft rates: Exploitation Less LikelyKB5002748KB50028301 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55944 ↗Microsoft Dynamics NAV 2018Critical2%Microsoft rates: Exploitation More Likely1 mentionsMicrosoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
CVE-2026-56159 ↗Windows 10 Version 1809 for 32-bit SystemsCritical1%Microsoft rates: Exploitation UnlikelyKB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
1 mentionsDHCP Server Service Remote Code Execution Vulnerability
CVE-2026-56188 ↗Windows 10 Version 1809 for 32-bit SystemsCritical1%Microsoft rates: Exploitation More LikelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsWindows Server Network driver Remote Code Execution Vulnerability
CVE-2026-56189 ↗Windows 10 Version 1809 for 32-bit SystemsCritical0%Microsoft rates: Exploitation Less LikelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsMicrosoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2026-57087 ↗Windows 10 Version 1809 for 32-bit SystemsCritical1%Microsoft rates: Exploitation Less LikelyKB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsMicrosoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2026-57090 ↗Windows 10 Version 1809 for 32-bit SystemsCritical1%Microsoft rates: Exploitation Less LikelyKB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsMicrosoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2026-57092 ↗Windows 10 Version 1809 for 32-bit SystemsCritical1%Microsoft rates: Exploitation Less LikelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Microsoft Windows VMSwitch Elevation of Privilege Vulnerability
CVE-2026-57094 ↗Windows 10 Version 1809 for 32-bit SystemsCritical1%Microsoft rates: Exploitation Less LikelyKB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsMicrosoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2026-58542 ↗Windows Server 2025 (Server Core installation)Critical0%Microsoft rates: Exploitation UnlikelyKB5099536KB5101649
and 1 moreKB5101650
1 mentionsWindows Media Remote Code Execution Vulnerability
CVE-2026-58608 ↗Windows 10 Version 1809 for 32-bit SystemsCritical1%Microsoft rates: Exploitation Less LikelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Print Spooler Remote Code Execution Vulnerability
CVE-2026-59873 ↗azl3 tar 1.35-2 on Azure Linux 3.0CriticalOut-of-band1%Microsoft rating unavailablenode-tar: Decompression/parse DoS via unlimited input
CVE-2026-26145 ↗Azure SynapseCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Azure Synapse Elevation of Privilege Vulnerability
CVE-2026-41106 ↗Microsoft 365 CopilotCriticalOut-of-band1%Microsoft rates: N/AMicrosoft 365 Copilot Elevation of Privilege Vulnerability
CVE-2026-45499 ↗Azure Open AICriticalOut-of-band1%Microsoft rates: N/AAzure OpenAI Elevation of Privilege Vulnerability
CVE-2026-54998 ↗Microsoft Exchange OnlineCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Exchange Online Elevation of Privilege Vulnerability
CVE-2026-57100 ↗Microsoft Entra Provisioning ServiceCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Entra Provisioning Service Elevation of Privilege Vulnerability
CVE-2026-63974 ↗azl3 kernel 6.6.145.2-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableBluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close
CVE-2026-63999 ↗azl3 kernel 6.6.145.2-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableethtool: rss: fix indir_table and hkey leak on get_rxfh failure
CVE-2026-64017 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableblk-mq: pop cached request if it is usable
CVE-2026-64076 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablenetfilter: bridge: eb_tables: close module init race
CVE-2026-63882 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailabledrm/amdkfd: fix NULL pointer bug in svm_range_set_attr
CVE-2026-64111 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablelsm: hold cred_guard_mutex for lsm_set_self_attr()
CVE-2026-63881 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailabledrm/amdkfd: fix a vulnerability of integer overflow in kfd debugger
CVE-2026-63983 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablenet/sched: fix packet loop on netem when duplicate is on
CVE-2026-64078 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablenetfilter: x_tables: add and use xtables_unregister_table_exit
CVE-2026-63958 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableusb: typec: ucsi: validate connector number in ucsi_connector_change()
CVE-2026-64070 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablepowerpc/hv-gpci: fix preempt count leak in sysfs show paths
CVE-2026-63959 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableusb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT
CVE-2026-64079 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablenetfilter: x_tables: allocate hook ops while under mutex
CVE-2026-63827 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableapparmor: fix use-after-free in rawdata dedup loop
CVE-2026-63814 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablef2fs: validate ACL entry sizes in f2fs_acl_from_disk()
CVE-2026-63828 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableapparmor: mediate the implicit connect of TCP fast open sendmsg
CVE-2026-63797 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablerpmsg: char: Fix use-after-free on probe error path
CVE-2026-63800 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablepNFS: Fix use-after-free in pnfs_update_layout()
CVE-2026-63824 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableKEYS: fix overflow in keyctl_pkey_params_get_2()
CVE-2026-63822 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablewifi: ath11k: fix warning when unbinding
CVE-2026-53384 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableserial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
CVE-2026-53387 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableiio: light: veml6075: add bounds check to veml6075_it_ms index
CVE-2026-63818 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablef2fs: validate orphan inode entry count
CVE-2026-63833 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablentfs3: reject direct userspace writes to reserved $LX* xattrs
CVE-2026-53376 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailabledrm/amdkfd: Add upper bound check for num_of_nodes
CVE-2026-53403 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablefbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
CVE-2026-53374 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: zero-initialize GART table on allocation
CVE-2026-53386 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableiio: adc: ti-ads1298: add bounds check to pga_settings index
CVE-2026-63816 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablef2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode
CVE-2026-60082 ↗azl3 perl-DBI 1.643-5 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableDBI versions before 1.651 for Perl do not enforce statement handle consistency with the row
CVE-2026-15043 ↗azl3 perl-DBI 1.643-5 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailableDBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text
CVE-2026-38968 ↗azl3 ntopng 5.2.1-6 on Azure Linux 3.0CriticalOut-of-bandNot availableMicrosoft rating unavailablentopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-54058trackedCVSS 9.1Red Hat Quay 3.15registry.redhat.io/quay/quay-rhel8@sha256:3773976a2937e59ee577d2f5c73f19b8204cc5347e23d2ae4cdd70759189d4f5_amd64Patch ↗Advisory ↗
Red HatCVE-2026-16242trackedCVSS 9.4multicluster engine for Kubernetes 2.8registry.redhat.io/multicluster-engine/hypershift-rhel9-operator@sha256:040b2b1d585944ed7456aa57afb4b1ff2a73aa8aff641edd0f1f6f185165ec89_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-16242trackedCVSS 9.4multicluster engine for Kubernetes 2.6registry.redhat.io/multicluster-engine/hypershift-rhel9-operator@sha256:102c21b5d058b8e7b1c541f32df239c20a06383edc806caef93e7ac2d3a27d71_arm64Patch ↗Advisory ↗
Red HatCVE-2026-16242trackedCVSS 9.4multicluster engine for Kubernetes 2.9registry.redhat.io/multicluster-engine/hypershift-rhel9-operator@sha256:31112fed243b910989083bf307ca1fd1e1a5d4f6dd477b35b13527990f6d5165_amd64Patch ↗Advisory ↗
Red HatCVE-2026-16242trackedCVSS 9.4multicluster engine for Kubernetes 2.11registry.redhat.io/multicluster-engine/hypershift-rhel9-operator@sha256:26855d3e9974fe5cae92e0d9c8897fc221d5c30fb202377e1ffc6496971a5119_amd64Patch ↗Advisory ↗
Red HatCVE-2026-16242trackedCVSS 9.4multicluster engine for Kubernetes 2.17registry.redhat.io/multicluster-engine/hypershift-rhel9-operator@sha256:8e318964446dcded1fc3982dbd9acdc28ae7cc606adad4542d54b63b0d0392ea_arm64Patch ↗Advisory ↗
Red HatCVE-2026-54058trackedCVSS 9.1Red Hat Enterprise Linux AppStream (v. 8)python-pillow-0:5.1.1-23.el8_10.srcPatch ↗Advisory ↗
Red HatCVE-2026-16242trackedCVSS 9.4multicluster engine for Kubernetes 2.1registry.redhat.io/multicluster-engine/hypershift-rhel9-operator@sha256:5f3f32d339927e83d33f2843cbdb498c495f03fa5d06a7cd283cf1f52102a729_s390xPatch ↗Advisory ↗
Red HatCVE-2026-16242trackedCVSS 9.4multicluster engine for Kubernetes 2.1registry.redhat.io/multicluster-engine/hypershift-rhel9-operator@sha256:5f3f32d339927e83d33f2843cbdb498c495f03fa5d06a7cd283cf1f52102a729_s390xPatch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Ansible Automation Platform 2.5 for RHEL 8python3.12-pulpcore-0:3.49.63-2.el8ap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Ansible Automation Platform 2.6 for RHEL 9python3.12-pulpcore-0:3.49.63-2.el9ap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Satellite 6.16 for RHEL 8python-pulpcore-0:3.49.39-2.el8pc.srcPatch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform-26/hub-rhel9@sha256:5869ecbb9f62357c9c9243ce9777a63af24e631a9f3328e82035b1e8896e3bde_arm64Patch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Ansible Automation Platform 2.7registry.redhat.io/ansible-automation-platform-27/hub-rhel9@sha256:0ca881174308716272587c6bb517529d6b48b170686ba113e63cea720fa9f76c_arm64Patch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Satellite 6.17 for RHEL 9python-pulpcore-0:3.63.21-2.el9pc.srcPatch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Satellite 6.18 for RHEL 9python3.12-pulpcore-0:3.73.30-2.el9pc.noarchPatch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Satellite 6.19 for RHEL 9python3.12-pulpcore-0:3.85.15-5.el9pc.noarchPatch ↗Advisory ↗
Red HatCVE-2026-14544trackedCVSS 9.8Red Hat Enterprise Linux AppStream (v. 9)hplip-0:3.21.2-6.el9_8.5.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-14544trackedCVSS 9.8Red Hat Enterprise Linux AppStream (v. 8)hplip-0:3.18.4-14.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-14544trackedCVSS 9.8Red Hat Enterprise Linux AppStream (v. 10)hplip-0:3.23.12-10.el10_2.5.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.15ose-azure-acr-image-credential-provider-0:4.15.0-202606231944.p2.g5638728.assembly.stream.el8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Enterprise Linux AppStream (v. 8)osbuild-composer-0:101.5-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.15registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:02f21fe59cdbbc54a590204ba32ac5939946ebd7f335484c033a5cd359cf9141_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.14registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:48ad6d16b3e440b82e03bd2790a1091d090d7bcb3b9709f6f9b1cdaf57fb4a10_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:2383f01f7bb41e30d85915c985e4a2ac14982af81f2ac6b71f2d47be7fb2ed49_amd64Patch ↗Advisory ↗
Red HatCVE-2026-8631CVSS 9.8Red Hat Enterprise Linux AppStream E4S (v.9.4)hplip-0:3.21.2-6.el9_4.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-8631CVSS 9.8Red Hat Enterprise Linux AppStream E4S (v.9.2)hplip-0:3.21.2-6.el9_2.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-8631CVSS 9.8Red Hat Enterprise Linux AppStream EUS (v. 10.0)hplip-0:3.23.12-8.el10_0.2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-27962CVSS 9.1Red Hat Quay 3.18registry.redhat.io/quay/quay-rhel9@sha256:14e7fd727c1dc74e19001952176a8354cbc97ec5b4643a4815b6ffbc6d76e224_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:1d7124312a528d6456483e4e577faa6b4b4435ecb1c8bc96cc39adbf69c367b1_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.19registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:0231f446a00653bc62ea571fb609907c9d770ff8d347975f30eee83201bb615c_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Logging for Red Hat OpenShift 6.2registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:161adf962803dfcc53ffedfe2cdda056760d227b0e39a9f71dd93aec8392630f_s390xPatch ↗Advisory ↗
Red HatCVE-2026-44172CVSS 9.1Red Hat Enterprise Linux AppStream EUS (v. 10.0)mariadb-connector-c-debuginfo-0:3.4.4-1.el10_0.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-8631CVSS 9.8Red Hat Enterprise Linux AppStream EUS (v.9.6)hplip-0:3.21.2-6.el9_6.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.13registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:f9cd57c2fa8f60ede8ddbb95439518c9f10f6f87268d198dd0058072144cdba8_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.12registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:ee4e01a568771e297956dda2186eebdee19e4957317d8a652a00e34203143d9b_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1OpenShift API for Data Protection 1.6registry.redhat.io/oadp/oadp-velero-rhel9@sha256:1a9757e2badab0d1ca54c5ac7f058ff7cdb64c1b2837f0f9559f3545eaf5f709_arm64Patch ↗Advisory ↗
Red HatCVE-2026-44172CVSS 9.1Red Hat Enterprise Linux AppStream (v. 10)mariadb-connector-c-debuginfo-0:3.4.4-2.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.21registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:2e0177e3f784858ef16c65d6f3db67dc70d23f37c245a64e2a92109eee7debef_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.20registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:042ab7c5d114f2bb7149f26c1bb2cab76d0ad763ea907fe6c9424dc10204a39c_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift AI 2.25registry.redhat.io/rhoai/odh-ta-lmes-driver-rhel9@sha256:349a4aa8f05f9940b73b28b1ed77fc0ae755c17bb7d510b3397f20ca4ce543b2_arm64Patch ↗Advisory ↗
Red HatCVE-2026-44727CVSS 9.0Red Hat Migration Toolkit for Applications 8.2registry.redhat.io/mta/mta-solution-server-rhel9@sha256:21fab4b77580795980fd60b24ab1d6a3cc159a9246beccd1c19938bca94edd23_amd64Patch ↗Advisory ↗
Red HatCVE-2026-48746CVSS 9.1Red Hat OpenShift AI 2.25registry.redhat.io/rhoai/odh-caikit-tgis-serving-rhel9@sha256:a0c8ff589a81bc631bd3adda0788b97aab32de3c63db56e18ae133dba0e8ebf6_arm64Patch ↗Advisory ↗
Red HatCVE-2026-48746CVSS 9.1Red Hat Migration Toolkit for Applications 8.2registry.redhat.io/mta/mta-solution-server-rhel9@sha256:21fab4b77580795980fd60b24ab1d6a3cc159a9246beccd1c19938bca94edd23_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Migration Toolkit 1.8registry.redhat.io/rhmtc/openshift-migration-controller-rhel8@sha256:c6c8c0043464e89cd453e08d1810f64f51beb257cdea7308bb834514458b07a1_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Openshift Data Foundation 4.18registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:420112898072e37fb7698a706176cd71288f104f7740848378b33bc36d377c96_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Openshift Data Foundation 4.19registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:0452d41383814479aac36c6ec8795b3090980515df082a12ee159ee0c8499d43_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Web Terminal 1.15registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:9c8a6913c0bb401ca4d0287382d758c8cb96f54aae78ad536b35552f7013bd4f_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Web Terminal 1.14registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:82ccda09508a62cc4676a4c1778d7653807ec3cd12defae229989935c5aed999_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Satellite 6.17 for RHEL 9yggdrasil-worker-forwarder-0:0.0.4-1.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Satellite 6.18 for RHEL 9yggdrasil-worker-forwarder-0:0.0.4-1.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Satellite 6.19 for RHEL 9yggdrasil-worker-forwarder-0:0.0.4-1.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-48746CVSS 9.1Red Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform-26/mcp-tools-rhel9@sha256:230ed627c49991f8052a3fa3f49edd50bd91b0d752853547d8a1c167aab88994_amd64Patch ↗Advisory ↗
Red HatCVE-2026-48746CVSS 9.1Red Hat Ansible Automation Platform 2.7registry.redhat.io/ansible-automation-platform-27/mcp-tools-rhel9@sha256:00f4047821293d2e2691f2c622ad5de474c983ed7d813b56c88d0d4c8b4f933b_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.14registry.redhat.io/openshift4/ose-machine-api-provider-gcp-rhel8@sha256:11f0aff7248c784102ce14166bf0786589b61f4bba53db2b81e8362ecfa7d434_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-azure-file-csi-driver-rhel9@sha256:1678fcaa8f9a3213482b6bf8f8a122c219175d5e45757f0d35bf244398b3227d_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Edge Manager 1.1registry.redhat.io/rhem/flightctl-alert-exporter-rhel10@sha256:46f199ef17120950d7e93c7a961f84d2323d8a5c43f5011e6ae627d345e0b068_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Openshift Data Foundation 4.20registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:330cae7d058b96317b8491b53d5dae3fb6375a47b5744b30c9df116b029aa664_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1RHEM 1.1 for RHEL 10flightctl-0:1.1.3-1.el10em.srcPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/ose-thanos-rhel9@sha256:27a533d3b627b61ef0e11b61e642c679cc93d1fd88e745388d9df243b98742b2_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.19registry.redhat.io/openshift4/ose-cloud-credential-rhel9-operator@sha256:66f434c4d616829fe9cfc0dd1c860bcdb02a5bec8f2a26a0800601b180651c6f_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Edge Manager 1.1registry.redhat.io/rhem/flightctl-alert-exporter-rhel9@sha256:beaacb4be3f6b8f814ea6581b92c34b56676ec49adc0428ed757731c14a56eae_amd64Patch ↗Advisory ↗
Red HatCVE-2026-45445CVSS 9.1Cost Management 4registry.redhat.io/costmanagement/costmanagement-metrics-rhel9-operator@sha256:093ff7d3b7e420f4cd6650314bea628408ec38e2965e770295f4a5eb8e9b97ea_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.22registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:071ca3c82c66dd3685da8b5aa89d869a8bd04665c1e9d41c3e1dd5197807233f_s390xPatch ↗Advisory ↗
Red HatCVE-2026-27140CVSS 9.0Red Hat OpenShift Container Platform 4.17registry.redhat.io/openshift4/ose-docker-builder-rhel9@sha256:0c3fa899ccfc2afcf1fe3dafe5accca04007c6f2a0a890907453bd12ba2fe265_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.12registry.redhat.io/openshift4/ose-openstack-cloud-controller-manager-rhel8@sha256:1e2a6a5f70bf563a0e8aaf0b0f7e290a8ff9f672b0de42837734487a8868ebd7_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.17ose-azure-acr-image-credential-provider-0:4.17.0-202606171749.p2.g5bcfbfd.assembly.stream.el8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.17registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:1842cea1adc06eb90eaa2812ae160901bd1a4354d3da8a1c608ab9dc3ba333df_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.17registry.redhat.io/openshift4/ose-aws-efs-csi-driver-container-rhel9@sha256:16975a72332dcdb234effb7ae718eaa5d58586cfd6ae2ca9efc6f0a4e8b88572_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift AI 3.3registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:16a1ace0003e1105c767d39218bc3029e5390f22a3af4c9cd9bb316e5d45d4db_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Edge Manager 1.0registry.redhat.io/rhem/flightctl-alert-exporter-rhel9@sha256:7e7958da7226d0bb3b19bc1447e8545d7d96988d0bde589fbdd649e011586a95_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1RHEM 1.0 for RHEL 9flightctl-0:1.0.3-1.el9em.srcPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Advanced Cluster Management for Kubernetes 2.14registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:2a6b24698fc9507613d57ba8cf0053dc29fe2c0cb6ab7c2eddd2efaf5e8b6a81_s390xPatch ↗Advisory ↗
Red HatCVE-2026-41607CVSS 9.1Red Hat Advanced Cluster Management for Kubernetes 2.14registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:2a6b24698fc9507613d57ba8cf0053dc29fe2c0cb6ab7c2eddd2efaf5e8b6a81_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.21registry.redhat.io/openshift4/ose-hypershift-rhel9@sha256:11003a01c8bac507ca523893cd6449b4ad4e5744f9ed493e564c7192f1e7d4a7_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.22registry.redhat.io/openshift4/ose-container-networking-plugins-rhel9@sha256:25cdfbd4b8c24019ef37236fbf25ee6bc78b46211738f3b3932e61e05e74025f_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.22registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9@sha256:11515d8447399d3c30278f5081aa3faf959d85b67af4a73fe9efe7e70408e589_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-34078CVSS 9.0Red Hat Enterprise Linux Server (v. 7 ELS)flatpak-0:1.12.9-3.el7_9.ppc64Patch ↗Advisory ↗
Red HatCVE-2026-48746CVSS 9.1Red Hat AI Inference Server 3.2registry.redhat.io/rhaiis/vllm-cuda-rhel9@sha256:6b93986199cc8e02e9672374938a2aac7b7452d1bf7d1a8a6445bfe1940f6328_amd64Patch ↗Advisory ↗
Red HatCVE-2026-48746CVSS 9.1Red Hat AI Inference Server 3.2registry.redhat.io/rhaiis/vllm-rocm-rhel9@sha256:7e61f6b8bbdf8c1e0b04de9ee6cfe0b6ff493a5bd4ad5dc52de2c308d2389d0f_amd64Patch ↗Advisory ↗

Glossary