CYBERSECURITYTRACKER
TRACKING7,811 stories in this site build1,697 vulnerability news stories in this site build
Vulnerabilities

July 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 3 vulnerabilities with exploitation detected in the wild this month. This defender-focused view covers 3,199 vulnerabilities across 7,398 returned patch records from 3 vendors. Filter the complete month, or browse the static page trail without JavaScript.

7,398all patch recordsClear filters210criticalShow these records3Microsoft exploitation detectedShow these records6Microsoft in the Known Exploited Vulnerabilities catalogShow these records2,885tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

My Stack only keeps records whose vendor you have pinned. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 32 of 37 · records 6,201 to 6,400 of 7,398

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-53361 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableaf_unix: Set gc_in_progress to true in unix_gc().
CVE-2026-14355 ↗azl3 php 8.3.31-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD
CVE-2026-8458 ↗azl3 curl 8.11.1-9 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablewrong reuse for different services
CVE-2026-14258 ↗azl3 dhcpcd 10.0.8-2 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableDhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling
CVE-2026-53357 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableBluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()
CVE-2026-56149 ↗azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableAllocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service
CVE-2026-49090 ↗azl3 rubygem-elasticsearch 8.9.0-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableUncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service
CVE-2026-53339 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablei2c: qcom-cci: Fix NULL pointer dereference in cci_remove()
CVE-2026-53349 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nf_conntrack: destroy stale expectfn expectations on unregister
CVE-2026-53352 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablesignal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()
CVE-2026-53353 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablehsr: Remove WARN_ONCE() in hsr_addr_is_self().
CVE-2026-53347 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledrm/virtio: Fix driver removal with disabled KMS
CVE-2026-53336 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenvmem: layouts: onie-tlv: fix hang on unknown types
CVE-2026-53337 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailablenet: bonding: fix NULL pointer dereference in bond_do_ioctl()
CVE-2026-53327 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailabledebugobjects: Do not fill_pool() if pi_blocked_on
CVE-2026-53332 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableslimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd
CVE-2026-53345 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandNot availableMicrosoft rating unavailableKVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying
CVE-2026-64532 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailablefs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}
CVE-2026-38752 ↗azl3 busybox 1.36.1-26 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailableA stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.
CVE-2026-58597 ↗Microsoft Edge (Chromium-based)LowOut-of-band1%Microsoft rating unavailableMicrosoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2026-58039 ↗azl3 nodejs 24.17.0-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableA flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
CVE-2026-56847 ↗azl3 nodejs 24.17.0-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableA flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
CVE-2026-6879 ↗azl3 python3 3.12.9-14 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableQuadratic Behavior in xml.etree.ElementPath Index Predicates
CVE-2026-15037 ↗azl3 qtbase 6.6.3-5 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableXML injection vulnerability in QDom comment, CDATA and processing-instruction serialization
CVE-2026-64549 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableBluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
CVE-2026-64546 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailabledrm/edid: fix OOB read in drm_parse_tiled_block()
CVE-2026-64512 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableACPI: CPPC: Suppress UBSAN warning caused by field misuse
CVE-2026-47059 ↗azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java san
CVE-2026-59846 ↗azl3 libssh 0.10.6-8 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableLibssh: libssh: information disclosure via proxycommand %r username expansion
CVE-2026-12547 ↗azl3 libsoup 3.4.4-17 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableLibsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch
CVE-2026-16517 ↗azl3 libarchive 3.7.7-6 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableLibarchive: libarchive: signed integer overflow in archive_write_zip_header
CVE-2026-56392 ↗azl3 coreutils 9.4-6 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableHeap-based Buffer Overflow in GNU coreutils
CVE-2026-26080 ↗azl3 haproxy 2.9.11-7 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableHAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.
CVE-2026-41637 ↗azl3 unbound 1.25.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableDegradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries
CVE-2026-42955 ↗azl3 unbound 1.25.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableExtra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records
CVE-2026-46582 ↗azl3 unbound 1.25.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableA wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path
CVE-2026-54478 ↗azl3 unbound 1.25.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableDNS Cookie bypass when combined with proxy-protocol use
CVE-2026-55708 ↗azl3 unbound 1.25.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablePrivacy/configuration issue when adding local data in views through 'unbound-control'
CVE-2026-44687 ↗azl3 unbound 1.25.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableOff-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN
CVE-2026-53910 ↗azl3 diffutils 3.10-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableHeap-based Buffer Overflow in GNU diffutils
CVE-2026-62994 ↗azl3 coredns 1.11.4-17 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableCoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-58254CVSS 6.5Red Hat Hardened Imagesnats-server2-12-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6475CVSS 6.7Red Hat Enterprise Linux AppStream E4S (v.8.8)libpq-0:13.23-1.el8_8.1.i686Patch ↗Advisory ↗
Red HatCVE-2026-9678CVSS 5.9Red Hat Enterprise Linux AppStream (v. 10)nodejs24-1:24.18.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-9678CVSS 5.9Red Hat Enterprise Linux AppStream (v. 10)nodejs-1:22.23.1-2.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-9678CVSS 5.9Red Hat Enterprise Linux AppStream (v. 9)nodejs-1:24.18.0-1.module+el9.8.0+24456+b244c3b4.aarch64::nodejs:24Patch ↗Advisory ↗
Red HatCVE-2026-9678CVSS 5.9Red Hat Enterprise Linux AppStream (v. 9)nodejs-1:22.23.1-1.module+el9.8.0+24457+996af7aa.aarch64::nodejs:22Patch ↗Advisory ↗
Red HatCVE-2026-11972CVSS 6.5Red Hat Hardened Imagespython3-14-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-11972CVSS 6.5Red Hat Hardened Imagespython3-11-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-11972CVSS 6.5Red Hat Hardened Imagespython3-13-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-11972CVSS 6.5Red Hat Hardened Imagespython3-12-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-48619CVSS 5.3Red Hat Hardened Imagesnodejs22-0:22.23.1-2.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-48928CVSS 4.2Red Hat Hardened Imagesnodejs22-0:22.23.1-2.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-48930CVSS 5.6Red Hat Hardened Imagesnodejs22-0:22.23.1-2.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-48934CVSS 4.3Red Hat Hardened Imagesnodejs22-0:22.23.1-2.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-55892CVSS 5.5Red Hat Hardened Imagesvim-0:9.2.780-1.hum1@srcPatch ↗Advisory ↗
Red HatCVE-2026-58055CVSS 5.4Red Hat Hardened Imagesnghttp2-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-59856CVSS 5.3Red Hat Hardened Imagesvim-0:9.2.780-1.hum1@srcPatch ↗Advisory ↗
Red HatCVE-2026-59857CVSS 5.5Red Hat Hardened Imagesvim-0:9.2.780-1.hum1@srcPatch ↗Advisory ↗
Red HatCVE-2026-59858CVSS 6.5Red Hat Hardened Imagesvim-0:9.2.780-1.hum1@srcPatch ↗Advisory ↗
Red HatCVE-2026-1002CVSS 5.3Streams for Apache Kafka 2.9.4Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-14684CVSS 5.0Red Hat Hardened Imagescargo-0:1.96.1-1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-15187CVSS 4.3Red Hat Hardened Imagescargo-0:1.96.1-1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2340CVSS 6.5Red Hat OpenShift Container Platform 4.19rhcos-aarch64-4.19.9.6.202606241344-0Patch ↗Advisory ↗
Red HatCVE-2026-27980CVSS 5.3Streams for Apache Kafka 2.9.4Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-34480CVSS 5.3Streams for Apache Kafka 2.9.4Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-41506CVSS 6.5Red Hat Hardened Imagestrivy-0:0.72.0-0.1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47262CVSS 6.5Red Hat Hardened Imagestrivy-0:0.72.0-0.1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-50195CVSS 6.7Red Hat Hardened Imagestrivy-0:0.72.0-0.1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-54371CVSS 6.3Red Hat Hardened Imagesattr-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-54411CVSS 4.8Red Hat Hardened Imagespam-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-59946CVSS 5.6Red Hat Hardened Imagescomposer-main@noarchPatch ↗Advisory ↗
Red HatCVE-2026-6845CVSS 5.0Red Hat Hardened Imagesbinutils-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6860CVSS 5.3Streams for Apache Kafka 2.9.4Not reportedPatch ↗Advisory ↗
Red HatCVE-2024-34459CVSS 5.5Red Hat Insights proxy 1.5registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:ab22b39e57764b0b91cf5576c7a59ce8b0eb9174d957b54fe95daf16580f0720_amd64Patch ↗Advisory ↗
Red HatCVE-2024-42516CVSS 6.8Red Hat Enterprise Linux AppStream (v. 10)httpd-0:2.4.63-13.el10_2.4.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-13151CVSS 5.9Red Hat Insights proxy 1.5registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:ab22b39e57764b0b91cf5576c7a59ce8b0eb9174d957b54fe95daf16580f0720_amd64Patch ↗Advisory ↗
Red HatCVE-2025-22870CVSS 4.4Cluster Observability Operator 1.5.0registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9@sha256:2458650c46b90645dc9c0f271598baca1cf7aed76a63be523805eb654ddaab54_s390xPatch ↗Advisory ↗
Red HatCVE-2025-22872CVSS 6.5Cluster Observability Operator 1.5.0registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9@sha256:2458650c46b90645dc9c0f271598baca1cf7aed76a63be523805eb654ddaab54_s390xPatch ↗Advisory ↗
Red HatCVE-2025-47911CVSS 5.3Cluster Observability Operator 1.5.0registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9@sha256:2458650c46b90645dc9c0f271598baca1cf7aed76a63be523805eb654ddaab54_s390xPatch ↗Advisory ↗
Red HatCVE-2025-5278CVSS 4.4Red Hat Insights proxy 1.5registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:ab22b39e57764b0b91cf5576c7a59ce8b0eb9174d957b54fe95daf16580f0720_amd64Patch ↗Advisory ↗
Red HatCVE-2025-58190CVSS 4.3Cluster Observability Operator 1.5.0registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9@sha256:2458650c46b90645dc9c0f271598baca1cf7aed76a63be523805eb654ddaab54_s390xPatch ↗Advisory ↗
Red HatCVE-2026-14355CVSS 5.6Red Hat Hardened Imagesphp-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-2291CVSS 6.5Red Hat Enterprise Linux AppStream EUS (v.9.6)dnsmasq-0:2.85-17.el9_6.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-24072CVSS 5.5Red Hat Enterprise Linux AppStream (v. 10)httpd-0:2.4.63-13.el10_2.4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-25680CVSS 6.5Cluster Observability Operator 1.5.0registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9@sha256:2458650c46b90645dc9c0f271598baca1cf7aed76a63be523805eb654ddaab54_s390xPatch ↗Advisory ↗
Red HatCVE-2026-31790CVSS 5.9Red Hat Insights proxy 1.5registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:ab22b39e57764b0b91cf5576c7a59ce8b0eb9174d957b54fe95daf16580f0720_amd64Patch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9Red Hat Enterprise Linux AppStream E4S (v.9.4)buildah-2:1.33.15-1.el9_4.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9Red Hat Enterprise Linux AppStream E4S (v.9.4)podman-4:4.9.4-20.el9_4.3.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9Red Hat Enterprise Linux AppStream E4S (v.9.4)skopeo-2:1.14.6-1.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9Red Hat Satellite 6.19 for RHEL 9yggdrasil-worker-forwarder-0:0.0.3-5.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-33006CVSS 4.8Red Hat Enterprise Linux AppStream (v. 10)httpd-0:2.4.63-13.el10_2.4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33245CVSS 4.2Red Hat OpenShift AI 3.4registry.redhat.io/rhoai/odh-mod-arch-automl-rhel9@sha256:181aedea4d725b0ccdce06a980be68ef9334043300c09ffb441801d44a12ab45_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33671CVSS 6.5Cluster Observability Operator 1.5.0registry.redhat.io/cluster-observability-operator/logging-console-plugin-pf4-rhel9@sha256:1a883d0526f205beab9dfc51c5ac32b6a494dd950465b319076bf3a72e05e798_s390xPatch ↗Advisory ↗
Red HatCVE-2026-33813CVSS 6.5Logging Subsystem for Red Hat OpenShift 6.4registry.redhat.io/openshift-logging/cluster-logging-rhel9-operator@sha256:036c4b69ad3fc3d21f3874a182250670ba05d85b92f4fb3246dbc9a1b0d5b2f1_arm64Patch ↗Advisory ↗
Red HatCVE-2026-34043CVSS 5.9Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-networking-console-plugin-rhel9@sha256:262bb2ebe2d0a01719d4e19d594566851718a4b99574d7d8eb4fbcd788c1101c_arm64Patch ↗Advisory ↗
Red HatCVE-2026-34180CVSS 5.0Red Hat Insights proxy 1.5registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:ab22b39e57764b0b91cf5576c7a59ce8b0eb9174d957b54fe95daf16580f0720_amd64Patch ↗Advisory ↗
Red HatCVE-2026-34181CVSS 6.3Red Hat Insights proxy 1.5registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:ab22b39e57764b0b91cf5576c7a59ce8b0eb9174d957b54fe95daf16580f0720_amd64Patch ↗Advisory ↗
Red HatCVE-2026-35177CVSS 4.1Red Hat Insights proxy 1.5registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:ab22b39e57764b0b91cf5576c7a59ce8b0eb9174d957b54fe95daf16580f0720_amd64Patch ↗Advisory ↗
Red HatCVE-2026-35177CVSS 4.1Red Hat Enterprise Linux AppStream E4S (v.8.8)vim-X11-2:8.0.1763-20.el8_8.2.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-35177CVSS 4.1Red Hat Enterprise Linux AppStream AUS (v.8.6)vim-X11-2:8.0.1763-19.el8_6.6.x86_64Patch ↗Advisory ↗
Red HatCVE-2026-35469CVSS 6.5Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/ose-cluster-node-tuning-rhel9-operator@sha256:04e81b8c76665e096a47c72b57852f2ebaf3ed3bb69516560c238382a8f7f4f0_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-35469CVSS 6.5Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9@sha256:07b34c95b7ede32a3972f7cdcf175c6576932bee34329bb59bf4f00076f49c6b_amd64Patch ↗Advisory ↗
Red HatCVE-2026-35469CVSS 6.5Red Hat OpenShift Container Platform 4.19registry.redhat.io/openshift4/ose-smb-csi-driver-rhel9@sha256:5b6705bd17c6dcc2c2a75baf5d7b34087e123a34b37a74c7161fe025ec855e9e_arm64Patch ↗Advisory ↗
Red HatCVE-2026-42506CVSS 5.4Cluster Observability Operator 1.5.0registry.redhat.io/cluster-observability-operator/distributed-tracing-console-plugin-pf4-rhel9@sha256:2458650c46b90645dc9c0f271598baca1cf7aed76a63be523805eb654ddaab54_s390xPatch ↗Advisory ↗
Red HatCVE-2026-42764CVSS 5.9Red Hat Insights proxy 1.5registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:ab22b39e57764b0b91cf5576c7a59ce8b0eb9174d957b54fe95daf16580f0720_amd64Patch ↗Advisory ↗
Red HatCVE-2026-42766CVSS 5.3Red Hat Insights proxy 1.5registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:ab22b39e57764b0b91cf5576c7a59ce8b0eb9174d957b54fe95daf16580f0720_amd64Patch ↗Advisory ↗
Red HatCVE-2026-42767CVSS 5.3Red Hat Insights proxy 1.5registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:ab22b39e57764b0b91cf5576c7a59ce8b0eb9174d957b54fe95daf16580f0720_amd64Patch ↗Advisory ↗
Red HatCVE-2026-42768CVSS 6.3Red Hat Insights proxy 1.5registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:ab22b39e57764b0b91cf5576c7a59ce8b0eb9174d957b54fe95daf16580f0720_amd64Patch ↗Advisory ↗
Red HatCVE-2026-42769CVSS 5.9Red Hat Insights proxy 1.5registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:ab22b39e57764b0b91cf5576c7a59ce8b0eb9174d957b54fe95daf16580f0720_amd64Patch ↗Advisory ↗
Red HatCVE-2026-42770CVSS 5.9Red Hat Insights proxy 1.5registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:ab22b39e57764b0b91cf5576c7a59ce8b0eb9174d957b54fe95daf16580f0720_amd64Patch ↗Advisory ↗
Red HatCVE-2026-43279CVSS 5.8Red Hat Enterprise Linux Real Time for NFV E4S (v.9.2)kernel-rt-0:5.14.0-284.178.1.rt14.463.el9_2.srcPatch ↗Advisory ↗
Red HatCVE-2026-43279CVSS 5.8Red Hat Enterprise Linux AppStream E4S (v.9.2)bpftool-debuginfo-0:7.0.0-284.178.1.el9_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-43951CVSS 6.5Red Hat Enterprise Linux AppStream (v. 10)httpd-0:2.4.63-13.el10_2.4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-43951CVSS 6.5Red Hat Enterprise Linux AppStream (v. 10)mod_http2-0:2.0.29-4.el10_2.2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-44119CVSS 5.5Red Hat Enterprise Linux AppStream (v. 10)httpd-0:2.4.63-13.el10_2.4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-44188CVSS 5.3Red Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform-26/lightspeed-rhel9@sha256:5a0a1932f8bcdf436f08f9d00fdb520feefad62061ce79426d44ecd7d01724a2_s390xPatch ↗Advisory ↗
Red HatCVE-2026-44431CVSS 5.9Red Hat Hardened Imagespython-rpds-py-0:2026.6.3-1.hum1@srcPatch ↗Advisory ↗
Red HatCVE-2026-44431CVSS 5.9Red Hat Ansible Automation Platform 2.6 for RHEL 9python3.12-urllib3-0:2.7.0-1.el9ap.noarchPatch ↗Advisory ↗
Red HatCVE-2026-44431CVSS 5.9Red Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform-26/gateway-rhel9@sha256:23ea476af89606789f91e647e952039bff83b5ace02440b2c11dccb9020cc0fb_amd64Patch ↗Advisory ↗
Red HatCVE-2026-44431CVSS 5.9Red Hat Satellite 6.19registry.redhat.io/satellite/iop-vmaas-rhel9@sha256:0239eafa03209b4a08d699af3cd7d42e14af4b9143bb985f415aa277a3e50a10_amd64Patch ↗Advisory ↗
Red HatCVE-2026-44431CVSS 5.9Red Hat Satellite 6.19registry.redhat.io/satellite/iop-puptoo-rhel9@sha256:4f98137fbd64e97e69072ffbbe8594bda750c11a72de2b8fbcfb33192b9eaa82_amd64Patch ↗Advisory ↗
Red HatCVE-2026-44431CVSS 5.9Red Hat Satellite 6.19registry.redhat.io/satellite/iop-host-inventory-rhel9@sha256:b75188c693e2e7309c250b0c3a6dc7be5f65f581886e24da980cde7ed5991ed8_amd64Patch ↗Advisory ↗
Red HatCVE-2026-44431CVSS 5.9Red Hat Satellite 6.19registry.redhat.io/satellite/iop-yuptoo-rhel9@sha256:31d0856cb63ad9e7443ea098da8fd3ad89031ab0c8d77db546285a46b525c6ec_amd64Patch ↗Advisory ↗
Red HatCVE-2026-44431CVSS 5.9Red Hat Satellite 6.19registry.redhat.io/satellite/iop-insights-engine-rhel9@sha256:3d1991c8f9a5cb13a2a67a1d2fad02067edfd58aebb0d039c6feb2c73f5f9aca_amd64Patch ↗Advisory ↗
Red HatCVE-2026-45409CVSS 5.3Red Hat Hardened Imagespython-rpds-py-0:2026.6.3-1.hum1@srcPatch ↗Advisory ↗
Red HatCVE-2026-47241CVSS 5.9Red Hat Hardened Imagesruby3-4-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-48619CVSS 5.3Red Hat Hardened Imagesnodejs24-0:24.18.0-0.2.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4867CVSS 5.3Cluster Observability Operator 1.5.0registry.redhat.io/cluster-observability-operator/logging-console-plugin-pf4-rhel9@sha256:1a883d0526f205beab9dfc51c5ac32b6a494dd950465b319076bf3a72e05e798_s390xPatch ↗Advisory ↗
Red HatCVE-2026-4878CVSS 6.7Red Hat OpenShift Container Platform 4.14rhcos-aarch64-414.92.202606231112-0Patch ↗Advisory ↗
Red HatCVE-2026-48928CVSS 4.2Red Hat Hardened Imagesnodejs24-0:24.18.0-0.2.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-4893CVSS 6.5Red Hat Enterprise Linux AppStream EUS (v.9.6)dnsmasq-0:2.85-17.el9_6.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-48930CVSS 5.6Red Hat Hardened Imagesnodejs24-0:24.18.0-0.2.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-48934CVSS 4.3Red Hat Hardened Imagesnodejs24-0:24.18.0-0.2.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-5135CVSS 6.5Red Hat Satellite 6.19 for RHEL 9foreman-0:3.18.0.7-1.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-5135CVSS 6.5Red Hat Satellite 6.17 for RHEL 9foreman-0:3.14.0.17-1.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-5135CVSS 6.5Red Hat Satellite 6.16 for RHEL 8foreman-0:3.12.0.17-1.el8sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-5135CVSS 6.5Red Hat Satellite 6.18 for RHEL 9foreman-0:3.16.0.17-1.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-5138CVSS 4.3Red Hat Satellite 6.19 for RHEL 9foreman-0:3.18.0.7-1.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-5138CVSS 4.3Red Hat Satellite 6.17 for RHEL 9foreman-0:3.14.0.17-1.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-5138CVSS 4.3Red Hat Satellite 6.16 for RHEL 8foreman-0:3.12.0.17-1.el8sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-5138CVSS 4.3Red Hat Satellite 6.18 for RHEL 9foreman-0:3.16.0.17-1.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-5142CVSS 6.5Red Hat Satellite 6.19 for RHEL 9foreman-0:3.18.0.7-1.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-5142CVSS 6.5Red Hat Satellite 6.17 for RHEL 9foreman-0:3.14.0.17-1.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-5142CVSS 6.5Red Hat Satellite 6.16 for RHEL 8foreman-0:3.12.0.17-1.el8sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-5142CVSS 6.5Red Hat Satellite 6.18 for RHEL 9foreman-0:3.16.0.17-1.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-54370CVSS 6.3Red Hat Hardened Imagesacl-0:2.4.0-0.1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6475CVSS 6.7Red Hat Enterprise Linux AppStream E4S (v.8.8)pg_repack-0:1.4.6-3.module+el8.5.0+11354+78b3c9c5.ppc64le::postgresql:12Patch ↗Advisory ↗
Red HatCVE-2026-6475CVSS 6.7Red Hat Enterprise Linux AppStream AUS (v.8.4)pgaudit-0:1.4.0-6.module+el8.4.0+11288+c193d6d7.src::postgresql:12Patch ↗Advisory ↗
Red HatCVE-2026-6475CVSS 6.7Red Hat Enterprise Linux AppStream AUS (v.8.4)pgaudit-0:1.5.0-1.module+el8.4.0+8873+b821c30a.src::postgresql:13Patch ↗Advisory ↗
Red HatCVE-2026-6735CVSS 5.4Red Hat Enterprise Linux AppStream (v. 8)apcu-panel-0:5.1.18-1.module+el8.10.0+22485+a3539972.noarch::php:7.4Patch ↗Advisory ↗
Red HatCVE-2026-7258CVSS 5.9Red Hat Enterprise Linux AppStream (v. 8)apcu-panel-0:5.1.18-1.module+el8.10.0+22485+a3539972.noarch::php:7.4Patch ↗Advisory ↗
Red HatCVE-2026-7261CVSS 5.6Red Hat Enterprise Linux AppStream (v. 8)apcu-panel-0:5.1.18-1.module+el8.10.0+22485+a3539972.noarch::php:7.4Patch ↗Advisory ↗
Red HatCVE-2026-7383CVSS 5.5Red Hat Insights proxy 1.5registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:ab22b39e57764b0b91cf5576c7a59ce8b0eb9174d957b54fe95daf16580f0720_amd64Patch ↗Advisory ↗
Red HatCVE-2026-9076CVSS 5.9Red Hat Insights proxy 1.5registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:ab22b39e57764b0b91cf5576c7a59ce8b0eb9174d957b54fe95daf16580f0720_amd64Patch ↗Advisory ↗
Red HatCVE-2026-75803trackedCVSS 3.7Red Hat Hardened Imageschunkah-0:0.6.0-3.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-59083trackedCVSS 3.7Red Hat Hardened Imagestomcat10-0:10.1.57-1.hum1@noarchPatch ↗Advisory ↗
Red HatCVE-2026-59084trackedCVSS 3.8Red Hat Hardened Imagestomcat10-0:10.1.57-1.hum1@noarchPatch ↗Advisory ↗
Red HatCVE-2026-59083trackedCVSS 3.7Red Hat Hardened Imagestomcat11-0:11.0.24-0.1.hum1@noarchPatch ↗Advisory ↗
Red HatCVE-2026-59084trackedCVSS 3.8Red Hat Hardened Imagestomcat11-0:11.0.24-0.1.hum1@noarchPatch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Temurin Build of OpenJDK 25.0.4Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-47059CVSS 3.7Temurin Build of OpenJDK 25.0.4Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-54696CVSS 3.7Red Hat Hardened Imagesruby3-4-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-55654CVSS 3.7Red Hat Enterprise Linux AppStream (v. 10)openssh-askpass-0:9.9p1-25.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-56847CVSS 3.3Red Hat Hardened Imagesnodejs24-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-54696CVSS 3.7Red Hat Hardened Imagesruby4-0-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-54787CVSS 3.1Red Hat Hardened Imagesspire1-14-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-54787CVSS 3.1Red Hat Hardened Imagestrivy-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-55654CVSS 3.7Red Hat Enterprise Linux AppStream (v. 9)openssh-askpass-0:9.9p1-9.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-56847CVSS 3.3Red Hat Hardened Imagesnodejs26-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-56847CVSS 3.3Red Hat Hardened Imagesnodejs22-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6879CVSS 2.2Red Hat Hardened Imagespython3-14-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6879CVSS 2.2Red Hat Hardened Imagespython3-10-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6879CVSS 2.2Red Hat Hardened Imagespython3-11-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6879CVSS 2.2Red Hat Hardened Imagespython3-13-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6879CVSS 2.2Red Hat Hardened Imagespython3-12-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream (v. 10)firefox-0:140.13.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream (v. 8)firefox-0:140.13.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-56764CVSS 3.7Red Hat Hardened Imagesgrafana13.1-0:13.1.1-0.2.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-56764CVSS 3.7Red Hat Hardened Imagesgrafana12.4-0:12.4.6-0.2.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2025-6170CVSS 2.5Red Hat Discovery 2registry.redhat.io/discovery/discovery-server-rhel9@sha256:0c4f21c943641c8b229a8f018be12cb4a833ab5acd02b3bebc427bfb47635f47_arm64Patch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Hardened Imagesjava-25-openjdk-portable-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47059CVSS 3.7Red Hat Hardened Imagesjava-25-openjdk-portable-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-48617CVSS 2.9Red Hat Hardened Imagesnodejs24-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-11525CVSS 3.7Red Hat Hardened Imagesnodejs26-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-48617CVSS 2.9Red Hat Hardened Imagesnodejs26-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-48617CVSS 2.9Red Hat Hardened Imagesnodejs22-0:22.23.1-2.3.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2025-6170CVSS 2.5Red Hat Update Infrastructure 5registry.redhat.io/rhui5/cds-kubernetes-rhel9@sha256:434630073ec81d616b326e2e33538a3b93ea1f6656ebce21538077ac92e1fc02_amd64Patch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Enterprise Linux Server (v. 7 ELS)java-1.8.0-openjdk-1:1.8.0.502.b07-1.1.el7_9.i686Patch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Enterprise Linux AppStream (v. 8)java-1.8.0-openjdk-1:1.8.0.502.b07-1.1.el8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Build of OpenJDK 8u502Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Build of OpenJDK 8u502Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat OpenJDK 11 ELS for RHEL 7java-11-openjdk-1:11.0.32.0.9-1.el7_9.s390xPatch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7OPENJDK ELS 11.0.32Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7OPENJDK ELS 11.0.32Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Enterprise Linux AppStream (v. 8)java-17-openjdk-1:17.0.20.0.8-1.1.el8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Build of OpenJDK 17.0.20Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Build of OpenJDK 17.0.20Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Enterprise Linux AppStream EUS (v. 10.0)java-21-openjdk-1:21.0.12.0.8-1.1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Build of OpenJDK 21.0.12Not reportedPatch ↗Advisory ↗

Glossary