CYBERSECURITYTRACKER
TRACKING7,931 stories in this site build1,728 vulnerability news stories in this site build
Vulnerabilities

July 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 3 vulnerabilities with exploitation detected in the wild this month. This defender-focused view covers 3,887 vulnerabilities across 16,502 returned patch records from 4 vendors. Filter the complete month, or browse the static page trail without JavaScript.

16,502all patch recordsClear filters743criticalShow these records3Microsoft exploitation detectedShow these records6Microsoft in the Known Exploited Vulnerabilities catalogShow these records14,592tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

My Stack only keeps records whose vendor you have pinned. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 1 of 83 · records 1 to 200 of 16,502

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-58644 ↗Microsoft SharePoint Enterprise Server 2016Critical16%Microsoft rates: Exploitation DetectedCISA KEVVulnCheckENISAKB5002873KB5002874
and 1 moreKB5002880
7 mentionsMicrosoft SharePoint Remote Code Execution Vulnerability
CVE-2026-56155 ↗Windows 10 Version 1809 for 32-bit SystemsImportant0%Microsoft rates: Exploitation DetectedCISA KEVVulnCheckENISAKB5099444KB5099445
and 4 moreKB5099535KB5099536KB5099538KB5099540
6 mentionsActive Directory Federation Services Elevation of Privilege Vulnerability
CVE-2026-56164 ↗Microsoft SharePoint Enterprise Server 2016Moderate1%Microsoft rates: Exploitation DetectedCISA KEVVulnCheckENISAKB5002882KB5002883
and 1 moreKB5002891
9 mentionsMicrosoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2026-50522 ↗Microsoft SharePoint Enterprise Server 2016Critical3%Microsoft rates: Exploitation More LikelyCISA KEVVulnCheckENISAKB5002882KB5002883
and 1 moreKB5002891
7 mentionsMicrosoft SharePoint Remote Code Execution Vulnerability
CVE-2026-55040 ↗Microsoft SharePoint Enterprise Server 2016Critical18%Microsoft rates: Exploitation More LikelyCISA KEVVulnCheckENISAKB5002882KB5002883
and 1 moreKB5002891
8 mentionsMicrosoft SharePoint Server Security Feature Bypass Vulnerability
CVE-2026-53362 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableCISA KEVVulnCheckENISA1 mentionsipv6: account for fraggap on the paged allocation path
CVE-2026-11564 ↗azl3 rust 1.75.0-30 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailableNative CA trust persist
CVE-2026-48144 ↗azl3 thrift 0.15.0-6 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailableApache Thrift: c_glib TLS Client Missing Hostname Verification
CVE-2026-66803 ↗Azure Cosmos DBCriticalOut-of-band1%Microsoft rates: Exploitation Less LikelyAzure Cosmos DB Remote Code Execution Vulnerability
CVE-2026-64319 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band1%Microsoft rating unavailablenvmet-auth: validate reply message payload bounds against transfer length
CVE-2026-35425 ↗Azure API Management (APIM)CriticalOut-of-band1%Microsoft rates: N/AAzure API Management (APIM) Remote Code Execution Vulnerability
CVE-2026-49159 ↗Microsoft GraphCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Graph Information Disclosure Vulnerability
CVE-2026-50517 ↗Microsoft 365 CopilotCriticalOut-of-band2%Microsoft rates: N/AMicrosoft M365 Copilot Remote Code Execution Vulnerability
CVE-2026-54120 ↗Surface Management ServicesCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Surface Remote Code Execution Vulnerability
CVE-2026-56160 ↗Azure Red Hat OpenShift (ARO)CriticalOut-of-band1%Microsoft rates: N/AAzure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability
CVE-2026-56163 ↗Azure Kubernetes ServiceCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Azure Kubernetes Service Elevation of Privilege Vulnerability
CVE-2026-56165 ↗Microsoft AccountCriticalOut-of-band1%Microsoft rates: Exploitation Less LikelyMicrosoft Account Remote Code Execution Vulnerability
CVE-2026-56167 ↗Azure AI SearchCriticalOut-of-band1%Microsoft rates: N/AAzure AI Search Elevation of Privilege Vulnerability
CVE-2026-56191 ↗Microsoft Exchange OnlineCriticalOut-of-band1%Microsoft rates: N/AMicrosoft Exchange Online Tampering Vulnerability
CVE-2026-57106 ↗Microsoft Purview Data GovernanceCriticalOut-of-band1%Microsoft rates: N/AData Quality Elevation of Privilege Vulnerability
CVE-2026-58275 ↗Azure DNSCriticalOut-of-band1%Microsoft rates: N/AAzure DNS Elevation of Privilege Vulnerability
CVE-2026-58630 ↗Azure App Service for LinuxCriticalOut-of-band1%Microsoft rates: N/AAzure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
CVE-2026-62825 ↗Azure Key VaultCriticalOut-of-band1%Microsoft rates: N/AAzure Key Vault Elevation of Privilege Vulnerability
CVE-2026-62835 ↗Azure PortalCriticalOut-of-band1%Microsoft rates: N/AAzure Portal Information Disclosure Vulnerability
CVE-2026-63974 ↗azl3 kernel 6.6.145.2-1 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailableBluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close
CVE-2026-64017 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailableblk-mq: pop cached request if it is usable
CVE-2026-63979 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band1%Microsoft rating unavailablenet/handshake: hand off the pinned file reference to accept_doit
CVE-2026-64076 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailablenetfilter: bridge: eb_tables: close module init race
CVE-2026-64111 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailablelsm: hold cred_guard_mutex for lsm_set_self_attr()
CVE-2026-63881 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailabledrm/amdkfd: fix a vulnerability of integer overflow in kfd debugger
CVE-2026-64078 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailablenetfilter: x_tables: add and use xtables_unregister_table_exit
CVE-2026-64138 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band1%Microsoft rating unavailableksmbd: validate SID in parent security descriptor during ACL inheritance
CVE-2026-63827 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailableapparmor: fix use-after-free in rawdata dedup loop
CVE-2026-63814 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailablef2fs: validate ACL entry sizes in f2fs_acl_from_disk()
CVE-2026-63828 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailableapparmor: mediate the implicit connect of TCP fast open sendmsg
CVE-2026-63797 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailablerpmsg: char: Fix use-after-free on probe error path
CVE-2026-63800 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-band1%Microsoft rating unavailablepNFS: Fix use-after-free in pnfs_update_layout()
CVE-2026-63824 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailableKEYS: fix overflow in keyctl_pkey_params_get_2()
CVE-2026-53384 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0CriticalOut-of-band1%Microsoft rating unavailableserial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
CVE-2026-53387 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailableiio: light: veml6075: add bounds check to veml6075_it_ms index
CVE-2026-63818 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailablef2fs: validate orphan inode entry count
CVE-2026-63833 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailablentfs3: reject direct userspace writes to reserved $LX* xattrs
CVE-2026-53374 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailabledrm/amdgpu: zero-initialize GART table on allocation
CVE-2026-53386 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailableiio: adc: ti-ads1298: add bounds check to pga_settings index
CVE-2026-63816 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0CriticalOut-of-band0%Microsoft rating unavailablef2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode
CVE-2026-42533 ↗azl3 nginx 1.28.3-6 on Azure Linux 3.0CriticalOut-of-band1%Microsoft rating unavailable1 mentionsNGINX Map directive and Regex matching vulnerability
CVE-2026-57433 ↗azl3 perl 5.38.2-512 on Azure Linux 3.0CriticalOut-of-band1%Microsoft rating unavailableStorable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.15ose-azure-acr-image-credential-provider-0:4.15.0-202606231944.p2.g5638728.assembly.stream.el8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Enterprise Linux AppStream (v. 8)osbuild-composer-0:101.5-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.15registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:02f21fe59cdbbc54a590204ba32ac5939946ebd7f335484c033a5cd359cf9141_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.14registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:48ad6d16b3e440b82e03bd2790a1091d090d7bcb3b9709f6f9b1cdaf57fb4a10_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:2383f01f7bb41e30d85915c985e4a2ac14982af81f2ac6b71f2d47be7fb2ed49_amd64Patch ↗Advisory ↗
Red HatCVE-2026-54058trackedCVSS 9.1Red Hat Quay 3.15registry.redhat.io/quay/quay-rhel8@sha256:3773976a2937e59ee577d2f5c73f19b8204cc5347e23d2ae4cdd70759189d4f5_amd64Patch ↗Advisory ↗
Red HatCVE-2026-8631trackedCVSS 9.8Red Hat Enterprise Linux AppStream E4S (v.9.4)hplip-0:3.21.2-6.el9_4.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-8631trackedCVSS 9.8Red Hat Enterprise Linux AppStream E4S (v.9.2)hplip-0:3.21.2-6.el9_2.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-8631trackedCVSS 9.8Red Hat Enterprise Linux AppStream EUS (v. 10.0)hplip-0:3.23.12-8.el10_0.2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16242trackedCVSS 9.4multicluster engine for Kubernetes 2.8registry.redhat.io/multicluster-engine/hypershift-rhel9-operator@sha256:040b2b1d585944ed7456aa57afb4b1ff2a73aa8aff641edd0f1f6f185165ec89_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-16242trackedCVSS 9.4multicluster engine for Kubernetes 2.6registry.redhat.io/multicluster-engine/hypershift-rhel9-operator@sha256:102c21b5d058b8e7b1c541f32df239c20a06383edc806caef93e7ac2d3a27d71_arm64Patch ↗Advisory ↗
Red HatCVE-2026-16242trackedCVSS 9.4multicluster engine for Kubernetes 2.9registry.redhat.io/multicluster-engine/hypershift-rhel9-operator@sha256:31112fed243b910989083bf307ca1fd1e1a5d4f6dd477b35b13527990f6d5165_amd64Patch ↗Advisory ↗
Red HatCVE-2026-16242trackedCVSS 9.4multicluster engine for Kubernetes 2.11registry.redhat.io/multicluster-engine/hypershift-rhel9-operator@sha256:26855d3e9974fe5cae92e0d9c8897fc221d5c30fb202377e1ffc6496971a5119_amd64Patch ↗Advisory ↗
Red HatCVE-2026-16242trackedCVSS 9.4multicluster engine for Kubernetes 2.17registry.redhat.io/multicluster-engine/hypershift-rhel9-operator@sha256:8e318964446dcded1fc3982dbd9acdc28ae7cc606adad4542d54b63b0d0392ea_arm64Patch ↗Advisory ↗
Red HatCVE-2026-27962trackedCVSS 9.1Red Hat Quay 3.18registry.redhat.io/quay/quay-rhel9@sha256:14e7fd727c1dc74e19001952176a8354cbc97ec5b4643a4815b6ffbc6d76e224_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:1d7124312a528d6456483e4e577faa6b4b4435ecb1c8bc96cc39adbf69c367b1_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.19registry.redhat.io/openshift4/azure-kms-encryption-provider-rhel9@sha256:0231f446a00653bc62ea571fb609907c9d770ff8d347975f30eee83201bb615c_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Logging Subsystem for Red Hat OpenShift 6.2registry.redhat.io/openshift-logging/loki-rhel9-operator@sha256:161adf962803dfcc53ffedfe2cdda056760d227b0e39a9f71dd93aec8392630f_s390xPatch ↗Advisory ↗
Red HatCVE-2026-54058trackedCVSS 9.1Red Hat Enterprise Linux AppStream (v. 8)python-pillow-0:5.1.1-23.el8_10.srcPatch ↗Advisory ↗
SuseCVE-2026-57075trackedcritical (Suse rating)openSUSE Leap 16.0perl-YAML-Syck-0:1.470.0-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-57076trackedcritical (Suse rating)openSUSE Leap 16.0perl-YAML-Syck-0:1.470.0-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-57077trackedcritical (Suse rating)openSUSE Leap 16.0perl-YAML-Syck-0:1.470.0-bp160.1.1.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-8631trackedCVSS 9.8Red Hat Enterprise Linux AppStream EUS (v.9.6)hplip-0:3.21.2-6.el9_6.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16242trackedCVSS 9.4multicluster engine for Kubernetes 2.10registry.redhat.io/multicluster-engine/hypershift-rhel9-operator@sha256:5f3f32d339927e83d33f2843cbdb498c495f03fa5d06a7cd283cf1f52102a729_s390xPatch ↗Advisory ↗
Red HatCVE-2026-16242trackedCVSS 9.4multicluster engine for Kubernetes 2.10registry.redhat.io/multicluster-engine/hypershift-rhel9-operator@sha256:5f3f32d339927e83d33f2843cbdb498c495f03fa5d06a7cd283cf1f52102a729_s390xPatch ↗Advisory ↗
SuseCVE-2026-57075trackedcritical (Suse rating)openSUSE Leap 16.0perl-YAML-Syck-1.470.0-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-57076trackedcritical (Suse rating)openSUSE Leap 16.0perl-YAML-Syck-1.470.0-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-57077trackedcritical (Suse rating)openSUSE Leap 16.0perl-YAML-Syck-1.470.0-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2025-1020trackedCVSS 9.8openSUSE Tumbleweedfirefox-esr-0:153.0-1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2025-11717trackedCVSS 9.1openSUSE Tumbleweedfirefox-esr-0:153.0-1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2025-11719trackedCVSS 9.8openSUSE Tumbleweedfirefox-esr-0:153.0-1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2025-11721trackedCVSS 9.8openSUSE Tumbleweedfirefox-esr-0:153.0-1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-12293trackedCVSS 9.8openSUSE Tumbleweedfirefox-esr-0:153.0-1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-12316trackedCVSS 9.1openSUSE Tumbleweedfirefox-esr-0:153.0-1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-14241trackedCVSS 9.8openSUSE Tumbleweedfirefox-esr-0:153.0-1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16354trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16355trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16356trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16357trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16358trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16359trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16360trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16361trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16362trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16363trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16368trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16369trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16371trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16374trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16375trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16377trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16379trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16381trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16383trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16387trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16390trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16391trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16396trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16405trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16412trackedcritical (Suse rating)Open Enterprise Server 23.4MozillaFirefox-0:140.13.0-150200.152.248.1.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.13registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:f9cd57c2fa8f60ede8ddbb95439518c9f10f6f87268d198dd0058072144cdba8_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.12registry.redhat.io/openshift4/openshift-route-controller-manager-rhel8@sha256:ee4e01a568771e297956dda2186eebdee19e4957317d8a652a00e34203143d9b_amd64Patch ↗Advisory ↗
SuseCVE-2023-47248trackedCVSS 9.8openSUSE Tumbleweedpython313-pandas-0:3.0.3-1.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16354trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16355trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16356trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16357trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16358trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16359trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16360trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16361trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16362trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16363trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16368trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16369trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16371trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16374trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16375trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16377trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16379trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16381trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16383trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16387trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16390trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16391trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16396trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16405trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
SuseCVE-2026-16412trackedcritical (Suse rating)SUSE Linux Enterprise High Performance Computing 12 SP5MozillaFirefox-0:140.13.0-112.324.2.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1OpenShift API for Data Protection 1.6registry.redhat.io/oadp/oadp-velero-rhel9@sha256:1a9757e2badab0d1ca54c5ac7f058ff7cdb64c1b2837f0f9559f3545eaf5f709_arm64Patch ↗Advisory ↗
SuseCVE-2026-41176trackedCVSS 9.8openSUSE Leap 16.0rclone-0:1.74.4-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-41179trackedCVSS 9.8openSUSE Leap 16.0rclone-0:1.74.4-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-49980trackedcritical (Suse rating)openSUSE Leap 16.0rclone-0:1.74.4-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2018-7753trackedCVSS 9.8openSUSE Tumbleweedpython313-bleach-0:6.4.0-1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-31659trackedCVSS 9.8Open Enterprise Server 25.4kernel-64kb-0:6.4.0-150700.53.73.2.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.21registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:2e0177e3f784858ef16c65d6f3db67dc70d23f37c245a64e2a92109eee7debef_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.20registry.redhat.io/openshift4/kubevirt-csi-driver-rhel9@sha256:042ab7c5d114f2bb7149f26c1bb2cab76d0ad763ea907fe6c9424dc10204a39c_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift AI 2.25registry.redhat.io/rhoai/odh-ta-lmes-driver-rhel9@sha256:349a4aa8f05f9940b73b28b1ed77fc0ae755c17bb7d510b3397f20ca4ce543b2_arm64Patch ↗Advisory ↗
SuseCVE-2026-43011trackedCVSS 9.8Open Enterprise Server 25.4kernel-64kb-0:6.4.0-150700.53.73.2.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-44727trackedCVSS 9.0Red Hat Migration Toolkit for Applications 8.2registry.redhat.io/mta/mta-solution-server-rhel9@sha256:21fab4b77580795980fd60b24ab1d6a3cc159a9246beccd1c19938bca94edd23_amd64Patch ↗Advisory ↗
Red HatCVE-2026-45445trackedCVSS 9.1Red Hat Hardened Imageschunkah-0:0.6.0-3.hum1@aarch64Patch ↗Advisory ↗
SuseCVE-2026-4631trackedCVSS 9.8SUSE Linux Micro 6.2cockpit-0:364-160000.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-4631trackedCVSS 9.8SUSE Linux Enterprise Server 16.0cockpit-0:364-160000.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-4631trackedCVSS 9.8openSUSE Leap 16.0cockpit-0:364-160000.1.1.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-48746trackedCVSS 9.1Red Hat OpenShift AI 2.25registry.redhat.io/rhoai/odh-caikit-tgis-serving-rhel9@sha256:a0c8ff589a81bc631bd3adda0788b97aab32de3c63db56e18ae133dba0e8ebf6_arm64Patch ↗Advisory ↗
Red HatCVE-2026-48746trackedCVSS 9.1Red Hat Migration Toolkit for Applications 8.2registry.redhat.io/mta/mta-solution-server-rhel9@sha256:21fab4b77580795980fd60b24ab1d6a3cc159a9246beccd1c19938bca94edd23_amd64Patch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Ansible Automation Platform 2.5 for RHEL 8python3.12-pulpcore-0:3.49.63-2.el8ap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Ansible Automation Platform 2.6 for RHEL 9python3.12-pulpcore-0:3.49.63-2.el9ap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Satellite 6.16 for RHEL 8python-pulpcore-0:3.49.39-2.el8pc.srcPatch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform-26/hub-rhel9@sha256:5869ecbb9f62357c9c9243ce9777a63af24e631a9f3328e82035b1e8896e3bde_arm64Patch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Ansible Automation Platform 2.7registry.redhat.io/ansible-automation-platform-27/hub-rhel9@sha256:0ca881174308716272587c6bb517529d6b48b170686ba113e63cea720fa9f76c_arm64Patch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Satellite 6.17 for RHEL 9python-pulpcore-0:3.63.21-2.el9pc.srcPatch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Satellite 6.18 for RHEL 9python3.12-pulpcore-0:3.73.30-2.el9pc.noarchPatch ↗Advisory ↗
Red HatCVE-2026-12701trackedCVSS 9.0Red Hat Satellite 6.19 for RHEL 9python3.12-pulpcore-0:3.85.15-5.el9pc.noarchPatch ↗Advisory ↗
SuseCVE-2026-31659trackedCVSS 9.8SUSE Linux Enterprise Live Patching 15 SP7kernel-livepatch-6_4_0-150700_7_67-rt-0:1-150700.1.5.1.x86_64no patch linkAdvisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Migration Toolkit 1.8registry.redhat.io/rhmtc/openshift-migration-controller-rhel8@sha256:c6c8c0043464e89cd453e08d1810f64f51beb257cdea7308bb834514458b07a1_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Openshift Data Foundation 4.18registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:420112898072e37fb7698a706176cd71288f104f7740848378b33bc36d377c96_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Openshift Data Foundation 4.19registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:0452d41383814479aac36c6ec8795b3090980515df082a12ee159ee0c8499d43_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Web Terminal 1.15registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:9c8a6913c0bb401ca4d0287382d758c8cb96f54aae78ad536b35552f7013bd4f_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Web Terminal 1.14registry.redhat.io/web-terminal/web-terminal-tooling-rhel9@sha256:82ccda09508a62cc4676a4c1778d7653807ec3cd12defae229989935c5aed999_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Satellite 6.17 for RHEL 9yggdrasil-worker-forwarder-0:0.0.4-1.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Satellite 6.18 for RHEL 9yggdrasil-worker-forwarder-0:0.0.4-1.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Satellite 6.19 for RHEL 9yggdrasil-worker-forwarder-0:0.0.4-1.el9sat.srcPatch ↗Advisory ↗
SuseCVE-2026-43011trackedCVSS 9.8SUSE Linux Enterprise Live Patching 15 SP7kernel-livepatch-6_4_0-150700_7_67-rt-0:1-150700.1.5.1.x86_64no patch linkAdvisory ↗
Red HatCVE-2026-48746trackedCVSS 9.1Red Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform-26/mcp-tools-rhel9@sha256:230ed627c49991f8052a3fa3f49edd50bd91b0d752853547d8a1c167aab88994_amd64Patch ↗Advisory ↗
Red HatCVE-2026-48746trackedCVSS 9.1Red Hat Ansible Automation Platform 2.7registry.redhat.io/ansible-automation-platform-27/mcp-tools-rhel9@sha256:00f4047821293d2e2691f2c622ad5de474c983ed7d813b56c88d0d4c8b4f933b_amd64Patch ↗Advisory ↗
Red HatCVE-2026-14544trackedCVSS 9.8Red Hat Enterprise Linux AppStream (v. 9)hplip-0:3.21.2-6.el9_8.5.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-14544trackedCVSS 9.8Red Hat Enterprise Linux AppStream (v. 8)hplip-0:3.18.4-14.el8_10.aarch64Patch ↗Advisory ↗
SuseCVE-2026-15764trackedcritical (Suse rating)openSUSE Leap 16.0chromedriver-150.0.7871.124-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-15765trackedcritical (Suse rating)openSUSE Leap 16.0chromedriver-150.0.7871.124-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-15766trackedcritical (Suse rating)openSUSE Leap 16.0chromedriver-150.0.7871.124-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-15767trackedcritical (Suse rating)openSUSE Leap 16.0chromedriver-150.0.7871.124-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-15768trackedcritical (Suse rating)openSUSE Leap 16.0chromedriver-150.0.7871.124-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-15769trackedcritical (Suse rating)openSUSE Leap 16.0chromedriver-150.0.7871.124-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-15770trackedcritical (Suse rating)openSUSE Leap 16.0chromedriver-150.0.7871.124-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-15771trackedcritical (Suse rating)openSUSE Leap 16.0chromedriver-150.0.7871.124-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-15772trackedcritical (Suse rating)openSUSE Leap 16.0chromedriver-150.0.7871.124-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-15773trackedcritical (Suse rating)openSUSE Leap 16.0chromedriver-150.0.7871.124-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-15774trackedcritical (Suse rating)openSUSE Leap 16.0chromedriver-150.0.7871.124-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-15775trackedcritical (Suse rating)openSUSE Leap 16.0chromedriver-150.0.7871.124-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-15776trackedcritical (Suse rating)openSUSE Leap 16.0chromedriver-150.0.7871.124-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-15777trackedcritical (Suse rating)openSUSE Leap 16.0chromedriver-150.0.7871.124-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-15778trackedcritical (Suse rating)openSUSE Leap 16.0chromedriver-150.0.7871.124-bp160.1.1.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.14registry.redhat.io/openshift4/ose-machine-api-provider-gcp-rhel8@sha256:11f0aff7248c784102ce14166bf0786589b61f4bba53db2b81e8362ecfa7d434_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-azure-file-csi-driver-rhel9@sha256:1678fcaa8f9a3213482b6bf8f8a122c219175d5e45757f0d35bf244398b3227d_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Edge Manager 1.1registry.redhat.io/rhem/flightctl-alert-exporter-rhel10@sha256:46f199ef17120950d7e93c7a961f84d2323d8a5c43f5011e6ae627d345e0b068_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Openshift Data Foundation 4.20registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:330cae7d058b96317b8491b53d5dae3fb6375a47b5744b30c9df116b029aa664_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1RHEM 1.1 for RHEL 10flightctl-0:1.1.3-1.el10em.srcPatch ↗Advisory ↗
SuseCVE-2017-12620trackedCVSS 9.8openSUSE Tumbleweedopennlp-0:1.9.5-1.1.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-14544trackedCVSS 9.8Red Hat Enterprise Linux AppStream (v. 10)hplip-0:3.23.12-10.el10_2.5.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/ose-thanos-rhel9@sha256:27a533d3b627b61ef0e11b61e642c679cc93d1fd88e745388d9df243b98742b2_arm64Patch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat OpenShift Container Platform 4.19registry.redhat.io/openshift4/ose-cloud-credential-rhel9-operator@sha256:66f434c4d616829fe9cfc0dd1c860bcdb02a5bec8f2a26a0800601b180651c6f_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33186trackedCVSS 9.1Red Hat Edge Manager 1.1registry.redhat.io/rhem/flightctl-alert-exporter-rhel9@sha256:beaacb4be3f6b8f814ea6581b92c34b56676ec49adc0428ed757731c14a56eae_amd64Patch ↗Advisory ↗
Red HatCVE-2026-45445trackedCVSS 9.1Cost Management 4registry.redhat.io/costmanagement/costmanagement-metrics-rhel9-operator@sha256:093ff7d3b7e420f4cd6650314bea628408ec38e2965e770295f4a5eb8e9b97ea_amd64Patch ↗Advisory ↗

Glossary