CYBERSECURITYTRACKER
TRACKING3,763 stories692 vuln stories
Patch Day month

July 2026 vulnerabilities

A defender-focused view of 2,802 vulnerabilities across 4,864 returned patch records from 3 vendors. Filter the complete month, or browse the static page trail without JavaScript.

4,864all patch recordsClear filters190criticalShow these records3Microsoft exploitation detectedShow these records4Microsoft in CISA KEVShow these records1,950tracked hereShow these records

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as “no.” “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

Page 1 of 25 · records 1–200 of 4,864

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-58644 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Critical6%Exploitation detectedCISA KEVVulnCheckENISAKB5002873KB5002874
and 1 moreKB5002880
5 mentionsMicrosoft SharePoint Remote Code Execution Vulnerability
CVE-2026-56155 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsImportant2%Exploitation detectedCISA KEVVulnCheckENISAKB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
6 mentionsActive Directory Federation Services Elevation of Privilege Vulnerability
CVE-2026-56164 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Moderate22%Exploitation detectedCISA KEVVulnCheckENISAKB5002882KB5002883
and 1 moreKB5002891
8 mentionsMicrosoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2026-50522 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Critical77%More likelyCISA KEVVulnCheckENISAKB5002882KB5002883
and 1 moreKB5002891
5 mentionsMicrosoft SharePoint Remote Code Execution Vulnerability
CVE-2026-48144 ↗2026-08-07azl3 thrift 0.15.0-6 on Azure Linux 3.0CriticalOut-of-band0%Apache Thrift: c_glib TLS Client Missing Hostname Verification
CVE-2026-66803 ↗2026-07-30Azure Cosmos DBCriticalOut-of-band0%Azure Cosmos DB Remote Code Execution Vulnerability
CVE-2026-64319 ↗2026-07-26azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band1%nvmet-auth: validate reply message payload bounds against transfer length
CVE-2026-35425 ↗2026-07-23Azure API Management (APIM)CriticalOut-of-band0%Azure API Management (APIM) Remote Code Execution Vulnerability
CVE-2026-49159 ↗2026-07-23Microsoft GraphCriticalOut-of-band1%Microsoft Graph Information Disclosure Vulnerability
CVE-2026-50517 ↗2026-07-23Microsoft 365 CopilotCriticalOut-of-band1%Microsoft M365 Copilot Remote Code Execution Vulnerability
CVE-2026-54120 ↗2026-07-23Surface Management ServicesCriticalOut-of-band1%Microsoft Surface Remote Code Execution Vulnerability
CVE-2026-56160 ↗2026-07-23Azure Red Hat OpenShift (ARO)CriticalOut-of-band1%Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability
CVE-2026-56163 ↗2026-07-23Azure Kubernetes ServiceCriticalOut-of-band1%Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CVE-2026-56165 ↗2026-07-23Microsoft AccountCriticalOut-of-band1%Microsoft Account Remote Code Execution Vulnerability
CVE-2026-56167 ↗2026-07-23Azure AI SearchCriticalOut-of-band0%Azure AI Search Elevation of Privilege Vulnerability
CVE-2026-56191 ↗2026-07-23Microsoft Exchange OnlineCriticalOut-of-band1%Microsoft Exchange Online Tampering Vulnerability
CVE-2026-57106 ↗2026-07-23Microsoft Purview Data GovernanceCriticalOut-of-band1%Data Quality Elevation of Privilege Vulnerability
CVE-2026-58275 ↗2026-07-23Azure DNSCriticalOut-of-band1%Azure DNS Elevation of Privilege Vulnerability
CVE-2026-58630 ↗2026-07-23Azure App Service for LinuxCriticalOut-of-band1%Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
CVE-2026-62825 ↗2026-07-23Azure Key VaultCriticalOut-of-band1%Azure Key Vault Elevation of Privilege Vulnerability
CVE-2026-62835 ↗2026-07-23Azure PortalCriticalOut-of-band1%Azure Portal Information Disclosure Vulnerability
CVE-2026-63979 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band1%net/handshake: hand off the pinned file reference to accept_doit
CVE-2026-64138 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band0%ksmbd: validate SID in parent security descriptor during ACL inheritance
CVE-2026-42533 ↗2026-07-19azl3 nginx 1.28.3-6 on Azure Linux 3.0CriticalOut-of-band4%1 mentionsNGINX Map directive and Regex matching vulnerability
CVE-2026-57433 ↗2026-07-17azl3 perl 5.38.2-512 on Azure Linux 3.0CriticalOut-of-band0%Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record
CVE-2026-42982 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5095051KB5099414
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
CVE-2026-48561 ↗2026-07-14Microsoft Edge Copilot for AndroidCritical1%1 mentionsMicrosoft Edge Copilot Remote Code Execution Vulnerability
CVE-2026-48564 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5094041KB5094042
and 4 moreKB5099535KB5099536KB5099538KB5099540
1 mentionsDHCP Server Service Remote Code Execution Vulnerability
CVE-2026-49164 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Active Directory Domain Services Remote Code Execution Vulnerability
CVE-2026-49796 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsWindows GDI+ Remote Code Execution Vulnerability
CVE-2026-50314 ↗2026-07-14Microsoft Office 365 for MacCritical0%KB50028871 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-50327 ↗2026-07-14Windows Server 2025 (Server Core installation)Critical0%More likelyKB5099536KB5101649
and 1 moreKB5101650
1 mentionsWindows Media Remote Code Execution Vulnerability
CVE-2026-50370 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%More likelyKB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
1 mentionsDHCP Server Service Remote Code Execution Vulnerability
CVE-2026-50380 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsWindows GDI+ Remote Code Execution Vulnerability
CVE-2026-50382 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
1 mentionsDirectX Graphics Kernel Remote Code Execution Vulnerability
CVE-2026-50392 ↗2026-07-14Windows 11 Version 25H2 for x64-based SystemsCritical0%KB5099536KB5101649
and 1 moreKB5101650
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
CVE-2026-50444 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
CVE-2026-50467 ↗2026-07-14Microsoft Office 2019 for 32-bit editionsCritical0%KB50028871 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-50474 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsRemote Desktop Client Remote Code Execution Vulnerability
CVE-2026-50518 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical11%More likelyKB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
1 mentionsWindows DHCP Server Remote Code Execution Vulnerability
CVE-2026-50655 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%More likelyKB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsMicrosoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2026-50680 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5099536KB5099538
and 4 moreKB5099539KB5099540KB5101649KB5101650
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2026-50694 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
CVE-2026-54117 ↗2026-07-14Microsoft SQL Server 2025 for x64-based Systems (GDR)Critical1%KB5101346KB5102333Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-54118 ↗2026-07-14Microsoft SQL Server 2016 for x64-based Systems Service Pack 3 Azure Connect Feature PackCritical1%KB5101346KB5101347
and 8 moreKB5102333KB5102334KB5102335KB5102336KB5102337KB5102338KB5102339KB5102340
Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2026-54121 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
1 mentionsActive Directory Certificate Services Elevation of Privilege Vulnerability
CVE-2026-54127 ↗2026-07-14Windows Server 2022Critical0%KB5099536KB5099540
and 2 moreKB5101649KB5101650
Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2026-54128 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsWindows DHCP Client Remote Code Execution Vulnerability
CVE-2026-54982 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsWindows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2026-54992 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsMicrosoft Message Queuing Queue Manager Remote Code Execution Vulnerability
CVE-2026-54995 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsWindows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2026-54999 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows TCP/IP Remote Code Execution Vulnerability
CVE-2026-55008 ↗2026-07-14Microsoft Exchange Server 2016 Cumulative Update 23Critical1%More likelyKB5103212KB5103213
and 2 moreKB5103214KB5103215
Microsoft Exchange Server Spoofing Vulnerability
CVE-2026-55010 ↗2026-07-14Minecraft Bedrock Dedicated ServerCritical1%More likely1 mentionsMinecraft Bedrock Dedicated Server Remote Code Execution Vulnerability
CVE-2026-55011 ↗2026-07-14Microsoft Malware Protection EngineCritical0%Microsoft Defender Remote Code Execution Vulnerability
CVE-2026-55012 ↗2026-07-14Microsoft Malware Protection EngineCritical0%Microsoft Defender Remote Code Execution Vulnerability
CVE-2026-55018 ↗2026-07-14Microsoft Office 365 for MacCritical0%KB50028871 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55022 ↗2026-07-14Microsoft Office 365 for MacCritical0%KB50028871 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55033 ↗2026-07-14Microsoft SharePoint Server 2019Critical1%KB5002882KB5002883
and 4 moreKB5002885KB5002890KB5002891KB5002892
1 mentionsMicrosoft Word Remote Code Execution Vulnerability
CVE-2026-55040 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Critical2%More likelyKB5002882KB5002883
and 1 moreKB5002891
3 mentionsMicrosoft SharePoint Server Security Feature Bypass Vulnerability
CVE-2026-55043 ↗2026-07-14Microsoft Office 365 for MacCritical0%KB50028671 mentionsMicrosoft PowerPoint Remote Code Execution Vulnerability
CVE-2026-55045 ↗2026-07-14Microsoft SharePoint Enterprise Server 2016Critical0%KB5002882KB5002883
and 4 moreKB5002885KB5002887KB5002891KB5002892
1 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55049 ↗2026-07-14Microsoft Office 2019 for 32-bit editionsCritical0%KB50027481 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55056 ↗2026-07-14Microsoft Office 2019 for 32-bit editionsCritical0%KB50028871 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55120 ↗2026-07-14Microsoft Office 2019 for 32-bit editionsCritical0%KB50028671 mentionsMicrosoft PowerPoint Remote Code Execution Vulnerability
CVE-2026-55123 ↗2026-07-14Microsoft Office 365 for MacCritical0%KB50028671 mentionsMicrosoft PowerPoint Remote Code Execution Vulnerability
CVE-2026-55127 ↗2026-07-14Microsoft SharePoint Server 2019Critical0%KB5002882KB5002883
and 4 moreKB5002885KB5002890KB5002891KB5002892
1 mentionsMicrosoft Word Remote Code Execution Vulnerability
CVE-2026-55129 ↗2026-07-14Microsoft Office 2019 for 32-bit editionsCritical0%KB50028871 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55132 ↗2026-07-14Microsoft Office 365 for MacCritical0%KB5002882KB5002883
and 4 moreKB5002885KB5002890KB5002891KB5002892
1 mentionsMicrosoft Word Remote Code Execution Vulnerability
CVE-2026-55140 ↗2026-07-14Microsoft Office 365 for MacCritical0%KB5002748KB50028301 mentionsMicrosoft Office Remote Code Execution Vulnerability
CVE-2026-55944 ↗2026-07-14Microsoft Dynamics NAV 2018Critical1%More likely1 mentionsMicrosoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
CVE-2026-56159 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
1 mentionsDHCP Server Service Remote Code Execution Vulnerability
CVE-2026-56188 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%More likelyKB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsWindows Server Network driver Remote Code Execution Vulnerability
CVE-2026-56189 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsMicrosoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2026-57087 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsMicrosoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2026-57090 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsMicrosoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2026-57092 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Microsoft Windows VMSwitch Elevation of Privilege Vulnerability
CVE-2026-57094 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical1%KB5099535KB5099536
and 5 moreKB5099538KB5099539KB5099540KB5101649KB5101650
1 mentionsMicrosoft Windows Media Foundation Remote Code Execution Vulnerability
CVE-2026-58542 ↗2026-07-14Windows Server 2025 (Server Core installation)Critical0%KB5099536KB5101649
and 1 moreKB5101650
1 mentionsWindows Media Remote Code Execution Vulnerability
CVE-2026-58608 ↗2026-07-14Windows 10 Version 1809 for 32-bit SystemsCritical0%KB5099444KB5099445
and 7 moreKB5099535KB5099536KB5099538KB5099539KB5099540KB5101649KB5101650
Windows Print Spooler Remote Code Execution Vulnerability
CVE-2026-59873 ↗2026-07-12azl3 tar 1.35-2 on Azure Linux 3.0CriticalOut-of-band0%node-tar: Decompression/parse DoS via unlimited input
CVE-2026-56000 ↗2026-07-09azl3 wayland 1.22.0-1 on Azure Linux 3.0CriticalOut-of-band0%xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()
CVE-2026-8926 ↗2026-07-04azl3 curl 8.11.1-9 on Azure Linux 3.0CriticalOut-of-band0%password leak with netrc and user in URL
CVE-2026-26145 ↗2026-07-02Azure SynapseCriticalOut-of-band0%Microsoft Azure Synapse Elevation of Privilege Vulnerability
CVE-2026-41106 ↗2026-07-02Microsoft 365 CopilotCriticalOut-of-band1%Microsoft 365 Copilot Elevation of Privilege Vulnerability
CVE-2026-45499 ↗2026-07-02Azure Open AICriticalOut-of-band1%Azure OpenAI Elevation of Privilege Vulnerability
CVE-2026-54998 ↗2026-07-02Microsoft Exchange OnlineCriticalOut-of-band1%Microsoft Exchange Online Elevation of Privilege Vulnerability
CVE-2026-57100 ↗2026-07-02Microsoft Entra Provisioning ServiceCriticalOut-of-band1%Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability
CVE-2026-63974 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandBluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close
CVE-2026-63999 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandethtool: rss: fix indir_table and hkey leak on get_rxfh failure
CVE-2026-64017 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandblk-mq: pop cached request if it is usable
CVE-2026-64076 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandnetfilter: bridge: eb_tables: close module init race
CVE-2026-63882 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-banddrm/amdkfd: fix NULL pointer bug in svm_range_set_attr
CVE-2026-64111 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandlsm: hold cred_guard_mutex for lsm_set_self_attr()
CVE-2026-63881 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-banddrm/amdkfd: fix a vulnerability of integer overflow in kfd debugger
CVE-2026-63983 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandnet/sched: fix packet loop on netem when duplicate is on
CVE-2026-64078 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandnetfilter: x_tables: add and use xtables_unregister_table_exit
CVE-2026-63958 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandusb: typec: ucsi: validate connector number in ucsi_connector_change()
CVE-2026-64070 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandpowerpc/hv-gpci: fix preempt count leak in sysfs show paths
CVE-2026-63959 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandusb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT
CVE-2026-64079 ↗2026-07-21azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandnetfilter: x_tables: allocate hook ops while under mutex
CVE-2026-63827 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandapparmor: fix use-after-free in rawdata dedup loop
CVE-2026-63814 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandf2fs: validate ACL entry sizes in f2fs_acl_from_disk()
CVE-2026-63828 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandapparmor: mediate the implicit connect of TCP fast open sendmsg
CVE-2026-63797 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandrpmsg: char: Fix use-after-free on probe error path
CVE-2026-63800 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandpNFS: Fix use-after-free in pnfs_update_layout()
CVE-2026-63824 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandKEYS: fix overflow in keyctl_pkey_params_get_2()
CVE-2026-63822 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandwifi: ath11k: fix warning when unbinding
CVE-2026-53384 ↗2026-07-20azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-bandserial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
CVE-2026-53387 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandiio: light: veml6075: add bounds check to veml6075_it_ms index
CVE-2026-63818 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandf2fs: validate orphan inode entry count
CVE-2026-63833 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandntfs3: reject direct userspace writes to reserved $LX* xattrs
CVE-2026-53376 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-banddrm/amdkfd: Add upper bound check for num_of_nodes
CVE-2026-53403 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandfbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
CVE-2026-53374 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-banddrm/amdgpu: zero-initialize GART table on allocation
CVE-2026-53386 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandiio: adc: ti-ads1298: add bounds check to pga_settings index
CVE-2026-63816 ↗2026-07-20azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-bandf2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode
CVE-2026-60082 ↗2026-07-17azl3 perl-DBI 1.643-5 on Azure Linux 3.0CriticalOut-of-bandDBI versions before 1.651 for Perl do not enforce statement handle consistency with the row
CVE-2026-15043 ↗2026-07-17azl3 perl-DBI 1.643-5 on Azure Linux 3.0CriticalOut-of-bandDBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text
CVE-2026-38968 ↗2026-07-09azl3 ntopng 5.2.1-6 on Azure Linux 3.0CriticalOut-of-bandntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.
CVE-2026-9547 ↗2026-07-04azl3 cmake 3.30.3-14 on Azure Linux 3.0CriticalOut-of-bandSSH improper host validation
CVE-2026-48586 ↗2026-08-07azl3 thrift 0.15.0-6 on Azure Linux 3.0ImportantOut-of-band1%Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size Limit
CVE-2026-58389 ↗2026-08-07azl3 thrift 0.15.0-6 on Azure Linux 3.0ImportantOut-of-band1%Apache Thrift: Rust binary protocol non-strict path missing string size limit
CVE-2026-43871 ↗2026-08-07azl3 thrift 0.15.0-6 on Azure Linux 3.0ImportantOut-of-band1%Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit
CVE-2026-55969 ↗2026-08-07azl3 thrift 0.15.0-6 on Azure Linux 3.0ImportantOut-of-band1%Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
CVE-2026-14257 ↗2026-08-07azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ImportantOut-of-band0%brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash
CVE-2026-55968 ↗2026-08-07azl3 thrift 0.15.0-6 on Azure Linux 3.0ImportantOut-of-band1%Apache Thrift: Node.js quadratic-time DoS in server receive transports
CVE-2026-58662 ↗2026-08-07azl3 thrift 0.15.0-6 on Azure Linux 3.0ImportantOut-of-band1%Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass
CVE-2026-55995 ↗2026-08-07azl3 isns-utils 0.102-1 on Azure Linux 3.0ImportantOut-of-band0%Double-free in the iSNS attribute decoder in open-iscsi

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-16242trackedCVSS 9.4multicluster engine for Kubernetes 2.8registry.redhat.io/multicluster-engine/hypershift-rhel9-operator@sha256:040b2b1d585944ed7456aa57afb4b1ff2a73aa8aff641edd0f1f6f185165ec89_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-16242trackedCVSS 9.4multicluster engine for Kubernetes 2.6registry.redhat.io/multicluster-engine/hypershift-rhel9-operator@sha256:102c21b5d058b8e7b1c541f32df239c20a06383edc806caef93e7ac2d3a27d71_arm64Patch ↗Advisory ↗
Red HatCVE-2026-16242trackedCVSS 9.4multicluster engine for Kubernetes 2.1registry.redhat.io/multicluster-engine/hypershift-rhel9-operator@sha256:5f3f32d339927e83d33f2843cbdb498c495f03fa5d06a7cd283cf1f52102a729_s390xPatch ↗Advisory ↗
Red HatCVE-2026-16242trackedCVSS 9.4multicluster engine for Kubernetes 2.1registry.redhat.io/multicluster-engine/hypershift-rhel9-operator@sha256:5f3f32d339927e83d33f2843cbdb498c495f03fa5d06a7cd283cf1f52102a729_s390xPatch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Ansible Automation Platform 2.5 for RHEL 8python3.12-pulpcore-0:3.49.63-2.el8ap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Ansible Automation Platform 2.6 for RHEL 9python3.12-pulpcore-0:3.49.63-2.el9ap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Satellite 6.16 for RHEL 8python-pulpcore-0:3.49.39-2.el8pc.srcPatch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform-26/hub-rhel9@sha256:5869ecbb9f62357c9c9243ce9777a63af24e631a9f3328e82035b1e8896e3bde_arm64Patch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Ansible Automation Platform 2.7registry.redhat.io/ansible-automation-platform-27/hub-rhel9@sha256:0ca881174308716272587c6bb517529d6b48b170686ba113e63cea720fa9f76c_arm64Patch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Satellite 6.17 for RHEL 9python-pulpcore-0:3.63.21-2.el9pc.srcPatch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Satellite 6.18 for RHEL 9python3.12-pulpcore-0:3.73.30-2.el9pc.noarchPatch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Satellite 6.19 for RHEL 9python3.12-pulpcore-0:3.85.15-5.el9pc.noarchPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.15ose-azure-acr-image-credential-provider-0:4.15.0-202606231944.p2.g5638728.assembly.stream.el8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Enterprise Linux AppStream (v. 8)osbuild-composer-0:101.5-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.15registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:02f21fe59cdbbc54a590204ba32ac5939946ebd7f335484c033a5cd359cf9141_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.14registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:48ad6d16b3e440b82e03bd2790a1091d090d7bcb3b9709f6f9b1cdaf57fb4a10_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:2383f01f7bb41e30d85915c985e4a2ac14982af81f2ac6b71f2d47be7fb2ed49_amd64Patch ↗Advisory ↗
Red HatCVE-2026-27962CVSS 9.1Red Hat Quay 3.18registry.redhat.io/quay/quay-rhel9@sha256:14e7fd727c1dc74e19001952176a8354cbc97ec5b4643a4815b6ffbc6d76e224_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:1d7124312a528d6456483e4e577faa6b4b4435ecb1c8bc96cc39adbf69c367b1_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.19registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:0231f446a00653bc62ea571fb609907c9d770ff8d347975f30eee83201bb615c_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Logging Subsystem for Red Hat OpenShift 6.2registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:161adf962803dfcc53ffedfe2cdda056760d227b0e39a9f71dd93aec8392630f_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.13registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:f9cd57c2fa8f60ede8ddbb95439518c9f10f6f87268d198dd0058072144cdba8_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.12registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:ee4e01a568771e297956dda2186eebdee19e4957317d8a652a00e34203143d9b_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1OpenShift API for Data Protection 1.6registry.redhat.io/oadp/oadp-velero-rhel9@sha256:1a9757e2badab0d1ca54c5ac7f058ff7cdb64c1b2837f0f9559f3545eaf5f709_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.21registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:2e0177e3f784858ef16c65d6f3db67dc70d23f37c245a64e2a92109eee7debef_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.20registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:042ab7c5d114f2bb7149f26c1bb2cab76d0ad763ea907fe6c9424dc10204a39c_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift AI 2.25registry.redhat.io/rhoai/odh-ta-lmes-driver-rhel9@sha256:349a4aa8f05f9940b73b28b1ed77fc0ae755c17bb7d510b3397f20ca4ce543b2_arm64Patch ↗Advisory ↗
Red HatCVE-2026-44727CVSS 9.0Red Hat Migration Toolkit for Applications 8.2registry.redhat.io/mta/mta-solution-server-rhel9@sha256:21fab4b77580795980fd60b24ab1d6a3cc159a9246beccd1c19938bca94edd23_amd64Patch ↗Advisory ↗
Red HatCVE-2026-48746CVSS 9.1Red Hat OpenShift AI 2.25registry.redhat.io/rhoai/odh-caikit-tgis-serving-rhel9@sha256:a0c8ff589a81bc631bd3adda0788b97aab32de3c63db56e18ae133dba0e8ebf6_arm64Patch ↗Advisory ↗
Red HatCVE-2026-48746CVSS 9.1Red Hat Migration Toolkit for Applications 8.2registry.redhat.io/mta/mta-solution-server-rhel9@sha256:21fab4b77580795980fd60b24ab1d6a3cc159a9246beccd1c19938bca94edd23_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Migration Toolkit 1.8registry.redhat.io/rhmtc/openshift-migration-controller-rhel8@sha256:c6c8c0043464e89cd453e08d1810f64f51beb257cdea7308bb834514458b07a1_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Openshift Data Foundation 4.18registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:420112898072e37fb7698a706176cd71288f104f7740848378b33bc36d377c96_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Openshift Data Foundation 4.19registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:0452d41383814479aac36c6ec8795b3090980515df082a12ee159ee0c8499d43_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Web Terminal 1.15registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:9c8a6913c0bb401ca4d0287382d758c8cb96f54aae78ad536b35552f7013bd4f_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Web Terminal 1.14registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:82ccda09508a62cc4676a4c1778d7653807ec3cd12defae229989935c5aed999_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Satellite 6.17 for RHEL 9yggdrasil-worker-forwarder-0:0.0.4-1.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Satellite 6.18 for RHEL 9yggdrasil-worker-forwarder-0:0.0.4-1.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Satellite 6.19 for RHEL 9yggdrasil-worker-forwarder-0:0.0.4-1.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-48746CVSS 9.1Red Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform-26/mcp-tools-rhel9@sha256:230ed627c49991f8052a3fa3f49edd50bd91b0d752853547d8a1c167aab88994_amd64Patch ↗Advisory ↗
Red HatCVE-2026-48746CVSS 9.1Red Hat Ansible Automation Platform 2.7registry.redhat.io/ansible-automation-platform-27/mcp-tools-rhel9@sha256:00f4047821293d2e2691f2c622ad5de474c983ed7d813b56c88d0d4c8b4f933b_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.14registry.redhat.io/openshift4/ose-machine-api-provider-gcp-rhel8@sha256:11f0aff7248c784102ce14166bf0786589b61f4bba53db2b81e8362ecfa7d434_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-azure-file-csi-driver-rhel9@sha256:1678fcaa8f9a3213482b6bf8f8a122c219175d5e45757f0d35bf244398b3227d_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Edge Manager 1.1registry.redhat.io/rhem/flightctl-alert-exporter-rhel10@sha256:46f199ef17120950d7e93c7a961f84d2323d8a5c43f5011e6ae627d345e0b068_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Openshift Data Foundation 4.2registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:330cae7d058b96317b8491b53d5dae3fb6375a47b5744b30c9df116b029aa664_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1RHEM 1.1 for RHEL 10flightctl-0:1.1.3-1.el10em.srcPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/ose-thanos-rhel9@sha256:27a533d3b627b61ef0e11b61e642c679cc93d1fd88e745388d9df243b98742b2_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.19registry.redhat.io/openshift4/ose-cloud-credential-rhel9-operator@sha256:66f434c4d616829fe9cfc0dd1c860bcdb02a5bec8f2a26a0800601b180651c6f_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Edge Manager 1.1registry.redhat.io/rhem/flightctl-alert-exporter-rhel9@sha256:beaacb4be3f6b8f814ea6581b92c34b56676ec49adc0428ed757731c14a56eae_amd64Patch ↗Advisory ↗
Red HatCVE-2026-45445CVSS 9.1Cost Management 4registry.redhat.io/costmanagement/costmanagement-metrics-rhel9-operator@sha256:093ff7d3b7e420f4cd6650314bea628408ec38e2965e770295f4a5eb8e9b97ea_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.22registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:071ca3c82c66dd3685da8b5aa89d869a8bd04665c1e9d41c3e1dd5197807233f_s390xPatch ↗Advisory ↗
Red HatCVE-2026-27140CVSS 9.0Red Hat OpenShift Container Platform 4.17registry.redhat.io/openshift4/ose-docker-builder-rhel9@sha256:0c3fa899ccfc2afcf1fe3dafe5accca04007c6f2a0a890907453bd12ba2fe265_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.12registry.redhat.io/openshift4/ose-openstack-cloud-controller-manager-rhel8@sha256:1e2a6a5f70bf563a0e8aaf0b0f7e290a8ff9f672b0de42837734487a8868ebd7_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.17ose-azure-acr-image-credential-provider-0:4.17.0-202606171749.p2.g5bcfbfd.assembly.stream.el8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.17registry.redhat.io/openshift4/aws-kms-encryption-provider-rhel9@sha256:1842cea1adc06eb90eaa2812ae160901bd1a4354d3da8a1c608ab9dc3ba333df_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.17registry.redhat.io/openshift4/ose-aws-efs-csi-driver-container-rhel9@sha256:16975a72332dcdb234effb7ae718eaa5d58586cfd6ae2ca9efc6f0a4e8b88572_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift AI 3.3registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:16a1ace0003e1105c767d39218bc3029e5390f22a3af4c9cd9bb316e5d45d4db_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Edge Manager 1.0registry.redhat.io/rhem/flightctl-alert-exporter-rhel9@sha256:7e7958da7226d0bb3b19bc1447e8545d7d96988d0bde589fbdd649e011586a95_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1RHEM 1.0 for RHEL 9flightctl-0:1.0.3-1.el9em.srcPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat Advanced Cluster Management for Kubernetes 2.14registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:2a6b24698fc9507613d57ba8cf0053dc29fe2c0cb6ab7c2eddd2efaf5e8b6a81_s390xPatch ↗Advisory ↗
Red HatCVE-2026-41607CVSS 9.1Red Hat Advanced Cluster Management for Kubernetes 2.14registry.redhat.io/rhacm2/acm-grafana-rhel9@sha256:2a6b24698fc9507613d57ba8cf0053dc29fe2c0cb6ab7c2eddd2efaf5e8b6a81_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.21registry.redhat.io/openshift4/ose-hypershift-rhel9@sha256:11003a01c8bac507ca523893cd6449b4ad4e5744f9ed493e564c7192f1e7d4a7_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.22registry.redhat.io/openshift4/ose-container-networking-plugins-rhel9@sha256:25cdfbd4b8c24019ef37236fbf25ee6bc78b46211738f3b3932e61e05e74025f_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.22registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9@sha256:11515d8447399d3c30278f5081aa3faf959d85b67af4a73fe9efe7e70408e589_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-38969Critical (Red Hat rating)Red Hat Hardened Imagesrust-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.14registry.redhat.io/openshift4/ose-cluster-olm-operator-rhel8@sha256:3c0cf2444e7888f331f64acd038631b689446983e124068b988ce0800fd56ddb_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.15registry.redhat.io/openshift4/ose-openstack-cloud-controller-manager-rhel9@sha256:129f011bf2bfc8abee7a67c2359e43e3ef3f471d785aa274f3e18974fd99d432_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.16ose-azure-acr-image-credential-provider-0:4.16.0-202606221818.p2.ga3ebdc0.assembly.stream.el8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-azure-cloud-controller-manager-rhel9@sha256:738e5f0211db71313812a104ad884d4ccf98a57742a8a764a25b82e181ead671_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186CVSS 9.1Logging Subsystem for Red Hat OpenShift 6.4registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:036c4b69ad3fc3d21f3874a182250670ba05d85b92f4fb3246dbc9a1b0d5b2f1_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33228CVSS 9.8Cluster Observability Operator 1.5.0registry.redhat.io/cluster-observability-operator/logging-console-plugin-pf4-rhel9@sha256:1a883d0526f205beab9dfc51c5ac32b6a494dd950465b319076bf3a72e05e798_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33937CVSS 9.8Cluster Observability Operator 1.5.0registry.redhat.io/cluster-observability-operator/logging-console-plugin-pf4-rhel9@sha256:1a883d0526f205beab9dfc51c5ac32b6a494dd950465b319076bf3a72e05e798_s390xPatch ↗Advisory ↗