CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Patch Day month

August 2026 vulnerabilities

A defender-focused view of 2,459 vulnerabilities across 3,874 returned patch records from 4 vendors. Filter the month to date, or browse the static page trail without JavaScript.

3,874all patch recordsClear filters183criticalShow these records1Microsoft exploitation detectedShow these records2Microsoft in CISA KEVShow these records1,062tracked hereShow these records

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as “no.” “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An EPSS percentage is the global 30-day exploitation probability in the wild, not specific to you.

Page 16 of 20 · records 3,001–3,200 of 3,874

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2024-14040 ↗azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ModerateOut-of-bandnet: nexthop: Increase weight to u16
CVE-2026-64297 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandmodule: decompress: check return value of module_extend_max_pages()
CVE-2026-64486 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: cmipci: check snd_ctl_new1() return value
CVE-2026-64331 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandusbip: vudc: fix NULL deref in vep_dequeue()
CVE-2026-64493 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandiio: pressure: mpl115: fix runtime PM leak on read error
CVE-2026-64276 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandInput: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count
CVE-2026-64352 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Allow LPM map access from sleepable BPF programs
CVE-2026-64465 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: xhci: Fix sleep in atomic context in xhci_free_streams()
CVE-2026-64458 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandmm/damon/ops-common: handle extreme intervals in damon_hot_score()
CVE-2026-64511 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandACPI: NFIT: core: Fix possible NULL pointer dereference
CVE-2026-64275 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandInput: elan_i2c - prevent division by zero and arithmetic underflow
CVE-2026-64364 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandHID: multitouch: fix out-of-bounds bit access on mt_io_flags
CVE-2026-64287 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU
CVE-2026-64332 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandUSB: ulpi: fix memory leak on registration failure
CVE-2026-64370 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandposix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path
CVE-2026-64363 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandHID: appleir: fix UAF on pending key_up_timer in remove()
CVE-2026-64373 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandcpufreq: Fix hotplug-suspend race during reboot
CVE-2026-64371 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandproc: protect ptrace_may_access() with exec_update_lock (part 1)
CVE-2026-64406 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: fix UAF in bt_accept_dequeue()
CVE-2026-64487 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser
CVE-2026-64390 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: track the connection owning a byte-range lock
CVE-2026-64412 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: ebtables: module names must be null-terminated
CVE-2026-64345 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: f_printer: take kref only for successful open
CVE-2026-64409 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work()
CVE-2026-64306 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandcrypto: drbg - Fix returning success on failure in CTR_DRBG
CVE-2026-64279 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandi2c: core: fix adapter deregistration race
CVE-2026-64338 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandUSB: misc: uss720: unregister parport on probe failure
CVE-2026-64507 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandx86/bugs: Enable IBPB flush on BPF JIT allocation
CVE-2026-64525 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandxfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit
CVE-2026-64374 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandsched/rt: Have RT_PUSH_IPI be default off for non PREEMPT_RT
CVE-2026-64348 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: free iso schedules on failed submit
CVE-2026-64425 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandio_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item
CVE-2026-64408 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: bnep: pin L2CAP connection during netdev registration
CVE-2026-64360 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandhfs/hfsplus: zero-initialize buffer in hfs_bnode_read
CVE-2026-64462 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandPCI: altera: Fix resource leaks on probe failure
CVE-2026-64277 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandInput: synaptics-rmi4 - bound the F3A keymap to the GPIO count
CVE-2026-64489 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: ymfpci: check snd_ctl_new1() return value
CVE-2026-64400 ↗azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: prevent path traversal bypass by restricting caseless retry
CVE-2026-64368 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandmm/slab: do not limit zeroing to orig_size when only red zoning is enabled
CVE-2026-64474 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandvfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc
CVE-2026-64326 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandblock: skip sync_blockdev() on surprise removal in bdev_mark_dead()
CVE-2026-64424 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandnetpoll: fix a use-after-free on shutdown path
CVE-2026-64388 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandsmb/client: fix chown/chgrp with SMB3 POSIX Extensions
CVE-2026-64346 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: gadget: udc: Fix use-after-free in gadget_match_driver
CVE-2026-64482 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: gus: check snd_ctl_new1() return value
CVE-2026-64324 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandudf: validate free block extents against the partition length
CVE-2026-64350 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandusb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info()
CVE-2026-64271 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandInput: touchwin - reset the packet index on every complete packet
CVE-2026-64488 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: aoa: check snd_ctl_new1() return value
CVE-2026-64272 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandInput: mms114 - fix touch indexing for MMS134S and MMS136
CVE-2026-64351 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: usb: kalmia: bound RX frame length in kalmia_rx_fixup()
CVE-2026-64429 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandgpio: eic-sprd: use raw_spinlock_t in the irq startup path
CVE-2026-64250 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandLoongArch: Report dying CPU to RCU in stop_this_cpu()
CVE-2026-64241 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandgpio: rockchip: teardown bugs and resource leaks
CVE-2026-64248 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandMIPS: smp: report dying CPU to RCU in stop_this_cpu()
CVE-2026-64433 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandBluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete
CVE-2026-64247 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: x86: hyper-v: Bound the bank index when querying sparse banks
CVE-2026-64396 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation
CVE-2026-64480 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: ice1712: check snd_ctl_new1() return value
CVE-2026-64378 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandwriteback: fix race between cgroup_writeback_umount() and inode_switch_wbs()
CVE-2026-47143 ↗azl3 rust 1.90.0-9 on Azure Linux 3.0ModerateOut-of-bandCapstone has a NULL Pointer Dereference with 3DNow! opcodes
CVE-2026-16615 ↗azl3 rest 0.9.0-1 on Azure Linux 3.0ModerateOut-of-bandLibrest: weak random number generation in pkce implementation
CVE-2026-46917 ↗azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Oracle Java SE: 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1
CVE-2026-47063 ↗azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients ru
CVE-2026-60147 ↗azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web
CVE-2026-59850 ↗azl3 libssh 0.10.6-8 on Azure Linux 3.0ModerateOut-of-bandLibssh: libssh: use-after-free via data callbacks on closed channels
CVE-2026-59844 ↗azl3 libssh 0.10.6-8 on Azure Linux 3.0ModerateOut-of-bandLibssh: libssh: denial of service via oversized sftp read length
CVE-2026-59845 ↗azl3 libssh 0.10.6-8 on Azure Linux 3.0ModerateOut-of-bandLibssh: libssh: denial of service via unchecked proxycommand fork() failure
CVE-2026-59847 ↗azl3 libssh 0.10.6-8 on Azure Linux 3.0ModerateOut-of-bandLibssh: libssh: integrity downgrade via openssl aes-gcm tag verification
CVE-2026-59843 ↗azl3 libssh 0.10.6-8 on Azure Linux 3.0ModerateOut-of-bandLibssh: libssh: denial of service via zero advertised channel packet size
CVE-2026-59848 ↗azl3 libssh 0.10.6-8 on Azure Linux 3.0ModerateOut-of-bandLibssh: libssh: denial of service via sftp responses with unknown request ids
CVE-2026-46600 ↗azl3 golang 1.25.12-1 on Azure Linux 3.0ModerateOut-of-bandParsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
CVE-2026-10723 ↗azl3 bind 9.20.23-1 on Azure Linux 3.0ModerateOut-of-bandIncorrect acceptance of NSEC3 records
CVE-2026-10822 ↗azl3 bind 9.20.23-1 on Azure Linux 3.0ModerateOut-of-bandKey Record using PRIVATEDNS algorithm may lead to unexpected exit
CVE-2026-44210 ↗azl3 kata-containers-cc 3.15.0.aks0-15 on Azure Linux 3.0ModerateOut-of-bandKata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod Annotations
CVE-2025-5278 ↗azl3 coreutils 9.4-6 on Azure Linux 3.0ModerateOut-of-bandCoreutils: heap buffer under-read in gnu coreutils sort via key specification
CVE-2026-59677 ↗azl3 checkpolicy 3.6-1 on Azure Linux 3.0ModerateOut-of-bandProcess Kill Attack Vector in killall() in seunshare
CVE-2026-59676 ↗azl3 checkpolicy 3.6-1 on Azure Linux 3.0ModerateOut-of-bandLocal File Deletion Attack Vector in rm_rf() in seunshare
CVE-2026-48525 ↗azl3 python-jwt 2.8.0-2 on Azure Linux 3.0ModerateOut-of-bandPyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
CVE-2026-48522 ↗azl3 python-jwt 2.8.0-2 on Azure Linux 3.0ModerateOut-of-bandPyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemes
CVE-2026-42769 ↗azl3 nodejs 24.14.1-3 on Azure Linux 3.0ModerateOut-of-bandTrust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate
CVE-2026-42767 ↗azl3 kata-containers 3.32.0.kata0-1 on Azure Linux 3.0ModerateOut-of-bandNULL Pointer Dereference in CRMF EncryptedValue Decryption
CVE-2026-42766 ↗azl3 kata-containers 3.32.0.kata0-1 on Azure Linux 3.0ModerateOut-of-bandPossible NULL Dereference in Password-Based CMS Decryption
CVE-2026-45446 ↗azl3 kata-containers 3.32.0.kata0-1 on Azure Linux 3.0ModerateOut-of-bandIncorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes
CVE-2026-44839 ↗azl3 rabbitmq-server 3.13.7-6 on Azure Linux 3.0ModerateOut-of-bandRabbitMQ: Unsanitized vhost names allow for XSS in management UI
CVE-2026-46181 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event()
CVE-2026-46130 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-banddm-verity-fec: fix reading parity bytes split across blocks (take 3)
CVE-2026-46147 ↗azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ModerateOut-of-bandKVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu()
CVE-2026-46241 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: mpc52xx: fix use-after-free on registration failure
CVE-2026-46153 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-band8021q: delete cleared egress QoS mappings
CVE-2026-46175 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix fsck inconsistency caused by FGGC of node block
CVE-2026-46171 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandriscv: kvm: fix vector context allocation leak
CVE-2026-46200 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandspi: mpc52xx: fix controller deregistration
CVE-2026-46076 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1
CVE-2026-46090 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandALSA: aloop: Fix peer runtime UAF during format-change stop
CVE-2026-45963 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandASoC: nau8821: Cancel delayed work on component remove
CVE-2026-45934 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: fix EEXIST abort due to non-consecutive gaps in chunk allocation
CVE-2026-45861 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandgfs2: Fix slab-use-after-free in qd_put
CVE-2026-46014 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: SVM: Add missing save/restore handling of LBR MSRs
CVE-2026-45949 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandhwrng: core - use RCU and work_struct to fix race condition
CVE-2026-46032 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: nSVM: Triple fault if restore host CR3 fails on nested #VMEXIT
CVE-2026-45859 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation
CVE-2026-46017 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmm: fix deferred split queue races during migration
CVE-2026-45897 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nft_counter: serialize reset with spinlock
CVE-2026-45943 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-banderofs: fix inline data read failure for ztailpacking pclusters
CVE-2026-45940 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: stmmac: fix oops when split header is enabled
CVE-2026-45961 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandgfs2: fix memory leaks in gfs2_fill_super error path
CVE-2026-45932 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Fix tcx/netkit detach permissions when prog fd isn't given
CVE-2026-45944 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandiommu/vt-d: Clear Present bit before tearing down context entry
CVE-2026-45855 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandata: libata-scsi: avoid Non-NCQ command starvation
CVE-2026-46066 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandceph: fix num_ops off-by-one when crypto allocation fails
CVE-2026-45894 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandiommu/vt-d: Clear Present bit before tearing down PASID entry
CVE-2026-45901 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nf_tables: revert commit_mutex usage in reset path
CVE-2026-46059 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN
CVE-2026-46071 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandKVM: nSVM: Avoid clearing VMCB_LBR in vmcb12
CVE-2026-45973 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/mlx5: Fix UMR hang in LAG error state unload
CVE-2026-45917 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandipvs: do not keep dest_dst if dev is going down
CVE-2026-45877 ↗azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ModerateOut-of-bandHID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients
CVE-2026-43029 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandmptcp: fix soft lockup in mptcp_recvmsg()
CVE-2025-68251 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-banderofs: avoid infinite loops due to corrupted subpage compact indexes
CVE-2026-43414 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ModerateOut-of-bandscsi: qla2xxx: Completely fix fcport double free
CVE-2025-38675 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandxfrm: state: initialize state_ptrs earlier in xfrm_state_find
CVE-2026-43465 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/mlx5e: RX, Fix XDP multi-buf frag counting for striding RQ
CVE-2026-43464 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ModerateOut-of-bandnet/mlx5e: RX, Fix XDP multi-buf frag counting for legacy RQ

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-48990CVSS 5.3Red Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform-26/lightspeed-chatbot-rhel9@sha256:1a440c21e1d882875a73201b3135957387f0d7846678b22b52732e984931099a_s390xPatch ↗Advisory ↗
Red HatCVE-2026-50020CVSS 5.3Red Hat JBoss Enterprise Application Platform 8.1Patch ↗Advisory ↗
Red HatCVE-2026-50560CVSS 5.3Red Hat JBoss Enterprise Application Platform 8.1Patch ↗Advisory ↗
Red HatCVE-2026-52923CVSS 5.8Red Hat Enterprise Linux NFV (v. 8)kernel-rt-0:4.18.0-553.151.1.rt7.492.el8_10.srcPatch ↗Advisory ↗
Red HatCVE-2026-52923CVSS 5.8Red Hat Enterprise Linux BaseOS (v. 8)bpftool-0:4.18.0-553.151.1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-5435CVSS 5.9Red Hat OpenShift distributed tracing 3.10.2registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:03fd3e2921ac7557fd5aa6b4d0714f9ee634efd1259b789638d478978fcd4f39_s390xPatch ↗Advisory ↗
Red HatCVE-2026-54370CVSS 6.3Red Hat OpenShift distributed tracing 3.10.2registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:03fd3e2921ac7557fd5aa6b4d0714f9ee634efd1259b789638d478978fcd4f39_s390xPatch ↗Advisory ↗
Red HatCVE-2026-5450CVSS 5.0Red Hat OpenShift distributed tracing 3.10.2registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:03fd3e2921ac7557fd5aa6b4d0714f9ee634efd1259b789638d478978fcd4f39_s390xPatch ↗Advisory ↗
Red HatCVE-2026-57236CVSS 6.5Red Hat Satellite 6.19 for RHEL 9rubygem-nokogiri-0:1.17.2-3.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-57236CVSS 6.5Red Hat Satellite 6.17 for RHEL 9rubygem-nokogiri-0:1.15.7-3.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-57236CVSS 6.5Red Hat Satellite 6.16 for RHEL 8rubygem-nokogiri-0:1.15.7-3.el8sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-57236CVSS 6.5Red Hat Satellite 6.18 for RHEL 9rubygem-nokogiri-0:1.15.7-3.el9sat.srcPatch ↗Advisory ↗
Red HatCVE-2026-5928CVSS 5.0Red Hat OpenShift distributed tracing 3.10.2registry.redhat.io/rhosdt/opentelemetry-collector-rhel9@sha256:03fd3e2921ac7557fd5aa6b4d0714f9ee634efd1259b789638d478978fcd4f39_s390xPatch ↗Advisory ↗
Red HatCVE-2026-60147CVSS 6.5Red Hat Hardened Imagesjava-21-openjdk-portable-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60147CVSS 6.5Red Hat Hardened Imagesjava-21-openjdk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2025-14087CVSS 5.6Red Hat Enterprise Linux CRB (v. 8)mingw-glib2-0:2.70.1-9.el8_10.srcPatch ↗Advisory ↗
Red HatCVE-2026-13757CVSS 6.2Red Hat Enterprise Linux AppStream (v. 9)p11-kit-client-debuginfo-0:0.26.4-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-13757CVSS 6.2Red Hat Enterprise Linux AppStream (v. 10)p11-kit-client-debuginfo-0:0.26.4-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-14899CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.13.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16358CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16358CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.13.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16371CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16371CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.13.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16374CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16374CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.13.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16375CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16375CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.13.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16377CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16377CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.13.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16379CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16379CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.13.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16381CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16381CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.13.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16383CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16383CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.13.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16387CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16387CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.13.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16390CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16390CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.13.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16391CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16391CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.13.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16396CVSS 6.1Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16396CVSS 6.1Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.13.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9Red Hat Enterprise Linux AppStream E4S (v.9.4)rhc-1:0.2.4-8.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9Red Hat Enterprise Linux AppStream (v. 10)osbuild-composer-0:165.1-3.el10_2.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-32281CVSS 5.9Red Hat Enterprise Linux AppStream E4S (v.9.2)rhc-1:0.2.2-1.el9_2.3.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-39833CVSS 5.5Red Hat Trusted Artifact Signer 1.4conforma-cli-stack-v1-4@amd64Patch ↗Advisory ↗
Red HatCVE-2026-40467CVSS 4.0Red Hat Hardened Imagesgawk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-40468CVSS 4.4Red Hat Hardened Imagesgawk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-40553CVSS 6.2Red Hat Hardened Imagesgawk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-44171CVSS 5.8Red Hat Enterprise Linux AppStream EUS (v. 10.0)mariadb-3:10.11.18-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47204CVSS 6.5Red Hat OpenShift Service Mesh 3.0registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:59fa6f408b345a25d7e9dd12cf79c5e56cae7a7c2d814ef32512346021485060_amd64Patch ↗Advisory ↗
Red HatCVE-2026-47204CVSS 6.5Red Hat OpenShift Service Mesh 3.1registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:94921265f210e84d79eeba8821c4527e81c36bfc7ce98f0cc8d64b44cbeef7a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-47204CVSS 6.5Red Hat OpenShift Service Mesh 3.2registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:a9893f3cced5ab9bafa20ae5f920cba27e852cc5e9f28b01a349a21d8f1ea63f_s390xPatch ↗Advisory ↗
Red HatCVE-2026-47204CVSS 6.5Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:09292f6545b2e6619bbbd267024fa4f9c6c8b760e53cfc2833eb54d9f453453e_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-47221CVSS 5.9Red Hat OpenShift Service Mesh 3.0registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:59fa6f408b345a25d7e9dd12cf79c5e56cae7a7c2d814ef32512346021485060_amd64Patch ↗Advisory ↗
Red HatCVE-2026-47221CVSS 5.9Red Hat OpenShift Service Mesh 3.1registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:94921265f210e84d79eeba8821c4527e81c36bfc7ce98f0cc8d64b44cbeef7a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-47221CVSS 5.9Red Hat OpenShift Service Mesh 3.2registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:a9893f3cced5ab9bafa20ae5f920cba27e852cc5e9f28b01a349a21d8f1ea63f_s390xPatch ↗Advisory ↗
Red HatCVE-2026-47221CVSS 5.9Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:09292f6545b2e6619bbbd267024fa4f9c6c8b760e53cfc2833eb54d9f453453e_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-48706CVSS 5.9Red Hat OpenShift Service Mesh 3.1registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:94921265f210e84d79eeba8821c4527e81c36bfc7ce98f0cc8d64b44cbeef7a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-48706CVSS 5.9Red Hat OpenShift Service Mesh 3.2registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:a9893f3cced5ab9bafa20ae5f920cba27e852cc5e9f28b01a349a21d8f1ea63f_s390xPatch ↗Advisory ↗
Red HatCVE-2026-48706CVSS 5.9Red Hat OpenShift Service Mesh 3.3registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:09292f6545b2e6619bbbd267024fa4f9c6c8b760e53cfc2833eb54d9f453453e_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-50262CVSS 5.5Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)tigervnc-0:1.1.0-25.el6_10.18.i686Patch ↗Advisory ↗
Red HatCVE-2026-50263CVSS 5.5Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)tigervnc-0:1.1.0-25.el6_10.18.i686Patch ↗Advisory ↗
Red HatCVE-2026-58010CVSS 6.5Red Hat Enterprise Linux CRB (v. 8)mingw-glib2-0:2.70.1-9.el8_10.srcPatch ↗Advisory ↗
Red HatCVE-2026-58011CVSS 6.5Red Hat Enterprise Linux CRB (v. 8)mingw-glib2-0:2.70.1-9.el8_10.srcPatch ↗Advisory ↗
Red HatCVE-2026-58012CVSS 6.5Red Hat Enterprise Linux CRB (v. 8)mingw-glib2-0:2.70.1-9.el8_10.srcPatch ↗Advisory ↗
Red HatCVE-2026-58013CVSS 6.5Red Hat Enterprise Linux CRB (v. 8)mingw-glib2-0:2.70.1-9.el8_10.srcPatch ↗Advisory ↗
Red HatCVE-2026-58015CVSS 5.9Red Hat Enterprise Linux CRB (v. 8)mingw-glib2-0:2.70.1-9.el8_10.srcPatch ↗Advisory ↗
Red HatCVE-2026-67315CVSS 5.8Red Hat Hardened Imagesgrafana13-1-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-67317CVSS 5.3Red Hat Hardened Imagesgrafana13-1-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-67318CVSS 5.3Red Hat Hardened Imagesgrafana13-1-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18477CVSS 4.4Red Hat Hardened Imagestar-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-67319CVSS 6.5Red Hat Hardened Imagesgrafana13-1-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-67319CVSS 6.5Red Hat Hardened Imagesgrafana12-4-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-69198CVSS 5.3Red Hat Hardened Imagesgrafana12-4-main@aarch64Patch ↗Advisory ↗