CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Patch Day month

August 2026 vulnerabilities

A defender-focused view of 2,459 vulnerabilities across 3,874 returned patch records from 4 vendors. Filter the month to date, or browse the static page trail without JavaScript.

3,874all patch recordsClear filters183criticalShow these records1Microsoft exploitation detectedShow these records2Microsoft in CISA KEVShow these records1,062tracked hereShow these records

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as “no.” “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An EPSS percentage is the global 30-day exploitation probability in the wild, not specific to you.

Page 19 of 20 · records 3,601–3,800 of 3,874

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2024-1543 ↗azl3 mariadb 10.11.6-3 on Azure Linux 3.0ModerateOut-of-bandAES T-Table sub-cache-line leakage
CVE-2024-1544 ↗azl3 mariadb 10.11.6-3 on Azure Linux 3.0ModerateOut-of-bandECDSA nonce bias caused by truncation
CVE-2024-5288 ↗azl3 mariadb 10.11.6-3 on Azure Linux 3.0ModerateOut-of-bandSafe-error attack on TLS 1.3 Protocol
CVE-2024-49978 ↗azl3 kernel 6.6.57.1-2 on Azure Linux 3.0ModerateOut-of-bandgso: fix udp gso fraglist segmentation after pull from frag_list
CVE-2024-49987 ↗azl3 kernel 6.6.57.1-2 on Azure Linux 3.0ModerateOut-of-bandbpftool: Fix undefined behavior in qsort(NULL 0 ...)
CVE-2024-49988 ↗azl3 kernel 6.6.57.1-2 on Azure Linux 3.0ModerateOut-of-bandksmbd: add refcnt to ksmbd_conn struct
CVE-2024-47678 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-bandicmp: change the order of rate limits
CVE-2024-47683 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Skip Recompute DSC Params if no Stream on Link
CVE-2024-47704 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Check link_res->hpo_dp_link_enc before using it
CVE-2024-47728 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-bandbpf: Zero former ARG_PTR_TO_{LONGINT} args in case of error
CVE-2024-49859 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix to check atomic_file in f2fs ioctl interfaces
CVE-2024-49905 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Add null check for 'afb' in amdgpu_dm_plane_handle_cursor_update (v2)
CVE-2024-49912 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Handle null 'stream_status' in 'planes_changed_for_existing_stream'
CVE-2024-46678 ↗azl3 kernel 6.6.51.1-5 on Azure Linux 3.0ModerateOut-of-bandbonding: change ipsec_lock from spin lock to mutex
CVE-2024-46762 ↗azl3 kernel 6.6.51.1-5 on Azure Linux 3.0ModerateOut-of-bandxen: privcmd: Fix possible access to a freed kirqfd instance
CVE-2024-46765 ↗azl3 kernel 6.6.51.1-5 on Azure Linux 3.0ModerateOut-of-bandice: protect XDP configuration with a mutex
CVE-2024-46803 ↗azl3 kernel 6.6.51.1-5 on Azure Linux 3.0ModerateOut-of-banddrm/amdkfd: Check debug trap enable before write dbg_ev_file
CVE-2024-27005 ↗azl3 hyperv-daemons 6.6.35.1-1 on Azure Linux 3.0ModerateOut-of-bandinterconnect: Don't access req_list while it's being manipulated
CVE-2024-35794 ↗azl3 hyperv-daemons 6.6.35.1-1 on Azure Linux 3.0ModerateOut-of-banddm-raid: really frozen sync_thread during suspend
CVE-2024-35808 ↗azl3 hyperv-daemons 6.6.35.1-1 on Azure Linux 3.0ModerateOut-of-bandmd/dm-raid: don't call md_reap_sync_thread() directly
CVE-2024-42067 ↗azl3 kernel 6.6.43.1-7 on Azure Linux 3.0ModerateOut-of-bandbpf: Take return from set_memory_rox() into account with bpf_jit_binary_lock_ro()
CVE-2024-1151 ↗azl3 hyperv-daemons 6.6.22.1-2 on Azure Linux 3.0ModerateOut-of-bandKernel: stack overflow problem in open vswitch kernel module leading to dos
CVE-2024-36009 ↗azl3 hyperv-daemons 6.6.35.1-1 on Azure Linux 3.0ModerateOut-of-bandax25: Fix netdev refcount issue
CVE-2020-29509 ↗azl3 golang 1.24.3-1 on Azure Linux 3.0ModerateOut-of-bandThe encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
CVE-2020-29511 ↗azl3 golang 1.24.3-1 on Azure Linux 3.0ModerateOut-of-bandThe encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
CVE-2021-20227 ↗sqlite-3.34.1-1.cm1.x86_64.rpm on CBL Mariner 1.0 x64ModerateOut-of-bandA flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.
CVE-2020-15358 ↗cm1 mysql 8.0.26-1 on CBL Mariner 1.0ModerateOut-of-bandIn SQLite before 3.32.3 select.c mishandles query-flattener optimization leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
CVE-2026-64532 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0LowOut-of-band0%
CVE-2025-46686 ↗cbl2 redis 6.2.18-3LowOut-of-band0%Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated user. This occurs because the server allocates memory for the command arguments of every bulk, even when the command is skipped because of insufficient permissions. NOTE: this is disputed by the Supplier because abuse of the commands network protocol is not a violation of the Redis Security Model.
CVE-2026-40556 ↗cbl2 nano 6.0-3LowOut-of-bandInsecure Directory Permissions in GNU nano Leading to Privilege Abuse
CVE-2025-11840 ↗cbl2 binutils 2.37-19LowOut-of-band0%GNU Binutils ldmisc.c vfinfo out-of-bounds
CVE-2025-2913 ↗cbl2 hdf5 1.14.4-1LowOut-of-band0%HDF5 H5FL.c H5FL__blk_gc_list use after free
CVE-2026-68304 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowwifi: brcmfmac: fix 802.1X-SHA256 call trace warning
CVE-2026-68229 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowmedia: cedrus: skip invalid H.264 reference list entries
CVE-2026-68209 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowmedia: sun4i-csi: Return queued buffers on start_streaming() failure
CVE-2026-68117 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowtipc: clear sock->sk on the failed-insert path in tipc_sk_create()
CVE-2026-68376 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowsctp: fix auth_hmacs array size in struct sctp_cookie
CVE-2026-68269 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowdrm/i915/gem: Add missing nospec on parallel submit slot
CVE-2026-68301 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lownet: hsr: fix memory leak on slave unregistration by removing synced VLANs
CVE-2026-68107 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0Lowdrm/amdgpu/vcn4: avoid rereading IB param length
CVE-2026-68248 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowdrm/i915: Return NULL on error in active_instance
CVE-2026-68309 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowwifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()
CVE-2026-68226 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowmedia: cx23885: add ioremap return check and cleanup
CVE-2026-68279 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowdrm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
CVE-2026-68417 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowRDMA/siw: publish QP after initialization
CVE-2026-68422 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowbtrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()
CVE-2026-68280 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowdrm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
CVE-2026-68277 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowdrm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
CVE-2026-68220 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowmedia: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe
CVE-2026-68234 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0Lowdrm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
CVE-2026-68403 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowwifi: brcmfmac: initialize SDIO data work before cleanup
CVE-2026-68355 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowwifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()
CVE-2026-68312 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0Lowcifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths
CVE-2026-68238 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0Lowdrm/amdgpu: Release VFCT ACPI table reference
CVE-2026-68302 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowamt: re-read skb header pointers after every pull
CVE-2026-68256 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowdrm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference
CVE-2026-68288 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0Lownet: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD
CVE-2026-68171 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowarm64: syscall: Ensure saved x0 is kept in-sync with tracer updates
CVE-2026-68363 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowwifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
CVE-2026-68244 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Lowdrm/i915/gem: Do not leak siblings[] on proto context error
CVE-2024-21243 ↗azl3 mysql 8.0.41-1 on Azure Linux 3.0LowOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Telemetry). Supported versions that are affected are 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 2.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).
CVE-2025-21546 ↗azl3 mysql 8.0.41-1 on Azure Linux 3.0LowOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).
CVE-2026-64571 ↗azl3 kernel 6.6.145.2-1 on Azure Linux 3.0LowOut-of-bandwifi: p54: validate RX frame length in p54_rx_eeprom_readback()
CVE-2024-21000 ↗azl3 mysql 8.0.41-1 on Azure Linux 3.0LowOut-of-bandVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).
CVE-2024-21244 ↗azl3 mysql 8.0.41-1 on Azure Linux 3.0LowOut-of-band
CVE-2026-18839 ↗azl3 rsync 3.4.3-1 on Azure Linux 3.0LowOut-of-bandPopt-devel: popt-static: size_t underflow in singleoptionhelp
CVE-2026-18739 ↗azl3 popt 1.19-1 on Azure Linux 3.0LowOut-of-bandPopt-devel: popt-static: off-by-one in poptstuffargs
CVE-2026-19023 ↗azl3 hdf5 1.14.6-4 on Azure Linux 3.0LowOut-of-bandHDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length String Datasets
CVE-2026-58039 ↗azl3 nodejs 24.17.0-1 on Azure Linux 3.0LowOut-of-band
CVE-2026-56847 ↗azl3 nodejs 24.17.0-1 on Azure Linux 3.0LowOut-of-band
CVE-2026-6879 ↗azl3 tensorflow 2.16.1-11 on Azure Linux 3.0LowOut-of-band
CVE-2026-15037 ↗azl3 qtbase 6.6.3-5 on Azure Linux 3.0LowOut-of-bandXML injection vulnerability in QDom comment, CDATA and processing-instruction serialization
CVE-2026-64549 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0LowOut-of-bandBluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
CVE-2026-64546 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0LowOut-of-banddrm/edid: fix OOB read in drm_parse_tiled_block()
CVE-2026-64512 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0LowOut-of-bandACPI: CPPC: Suppress UBSAN warning caused by field misuse
CVE-2026-47059 ↗azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0LowOut-of-bandVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java san
CVE-2026-59846 ↗azl3 libssh 0.10.6-8 on Azure Linux 3.0LowOut-of-bandLibssh: libssh: information disclosure via proxycommand %r username expansion
CVE-2026-16517 ↗azl3 libarchive 3.7.7-6 on Azure Linux 3.0LowOut-of-bandLibarchive: libarchive: signed integer overflow in archive_write_zip_header
CVE-2026-56392 ↗azl3 coreutils 9.4-7 on Azure Linux 3.0LowOut-of-bandHeap-based Buffer Overflow in GNU coreutils
CVE-2026-42770 ↗azl3 openssl 3.3.7-3 on Azure Linux 3.0LowOut-of-bandFFC-DH Peer Validation Uses Attacker-Supplied q
CVE-2026-42768 ↗azl3 openssl 3.3.7-1 on Azure Linux 3.0LowOut-of-bandMulti-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()
CVE-2026-46044 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0LowOut-of-bandipmi:ssif: Clean up kthread on errors
CVE-2026-45893 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowOut-of-bandapparmor: Fix & Optimize table creation from possibly unaligned memory
CVE-2026-43969 ↗azl3 rabbitmq-server 3.13.7-3 on Azure Linux 3.0LowOut-of-bandCookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
CVE-2026-3832 ↗cbl2 gnutls 3.7.11-6 on CBL Mariner 2.0LowOut-of-bandGnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response
CVE-2026-34743 ↗azl3 xz 5.4.4-2 on Azure Linux 3.0LowOut-of-bandXZ Utils: Buffer overflow in lzma_index_append()
CVE-2026-35388 ↗cbl2 openssh 8.9p1-9 on CBL Mariner 2.0LowOut-of-bandOpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
CVE-2026-3633 ↗azl3 libsoup 3.4.4-12 on Azure Linux 3.0LowOut-of-bandLibsoup: libsoup: header and http request injection via crlf injection
CVE-2026-3632 ↗azl3 libsoup 3.4.4-12 on Azure Linux 3.0LowOut-of-bandLibsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames
CVE-2026-3634 ↗cbl2 libsoup 3.0.4-12 on CBL Mariner 2.0LowOut-of-bandLibsoup: libsoup: http header injection and response splitting via crlf injection in content-type header
CVE-2026-0989 ↗cbl2 libxml2 2.10.4-9 on CBL Mariner 2.0LowOut-of-bandLibxml2: unbounded relaxng include recursion leading to stack overflow
CVE-2025-13837 ↗cbl2 python3 3.9.19-16 on CBL Mariner 2.0LowOut-of-bandOut-of-memory when loading Plist
CVE-2023-53012 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0LowOut-of-bandthermal: core: call put_device() only after device_register() fails
CVE-2024-36920 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0LowOut-of-bandscsi: mpi3mr: Avoid memcpy field-spanning write WARNING
CVE-2025-46394 ↗azl3 busybox 1.36.1-14 on Azure Linux 3.0LowOut-of-bandIn tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
CVE-2024-58251 ↗azl3 busybox 1.36.1-17 on Azure Linux 3.0LowOut-of-bandIn netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
CVE-2024-7598 ↗azl3 kubernetes 1.30.10-9 on Azure Linux 3.0LowOut-of-bandNetwork restriction bypass via race condition during namespace termination
CVE-2025-7069 ↗cbl2 hdf5 1.14.4-1 on CBL Mariner 2.0LowOut-of-bandHDF5 H5FSsection.c H5FS__sect_link_size heap-based overflow
CVE-2025-1180 ↗cbl2 gdb 11.2-6 on CBL Mariner 2.0LowOut-of-bandGNU Binutils ld elf-eh-frame.c _bfd_elf_write_section_eh_frame memory corruption
CVE-2025-1150 ↗azl3 binutils 2.41-7 on Azure Linux 3.0LowOut-of-bandGNU Binutils ld libbfd.c bfd_malloc memory leak
CVE-2025-29477 ↗cbl2 fluent-bit 3.0.6-2 on CBL Mariner 2.0LowOut-of-bandAn issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.
CVE-2025-29478 ↗cbl2 fluent-bit 3.0.6-2 on CBL Mariner 2.0LowOut-of-bandAn issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.
CVE-2025-2912 ↗cbl2 hdf5 1.14.4-1 on CBL Mariner 2.0LowOut-of-bandHDF5 H5Omessage.c H5O_msg_flush heap-based overflow
CVE-2025-2923 ↗azl3 hdf5 1.14.4.3-1 on Azure Linux 3.0LowOut-of-bandHDF5 H5Fint.c H5F_addr_encode_len heap-based overflow
CVE-2024-42155 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0LowOut-of-bands390/pkey: Wipe copies of protected- and secure-keys
CVE-2025-29923 ↗azl3 telegraf 1.31.0-10 on Azure Linux 3.0LowOut-of-bandgo-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment
CVE-2024-50211 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0LowOut-of-bandudf: refactor inode_bmap() to handle error
CVE-2024-47738 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0LowOut-of-bandwifi: mac80211: don't use rate mask for offchannel TX either
CVE-2026-19177 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19177 Insufficient validation of untrusted input in UI
CVE-2026-19176 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19176 Use after free in Skia
CVE-2026-19175 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19175 Use after free in Payments
CVE-2026-19174 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19174 Integer overflow in V8
CVE-2026-19173 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19173 Out of bounds write in Skia
CVE-2026-19172 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19172 Use after free in Views
CVE-2026-19171 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19171 Use after free in Media
CVE-2026-19170 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19170 Use after free in WebGL
CVE-2026-19169 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19169 Insufficient validation of untrusted input in Contextual Tasks
CVE-2026-19168 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19168 Inappropriate implementation in V8
CVE-2026-19167 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19167 Integer overflow in GPU
CVE-2026-19166 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19166 Use after free in Web Authentication
CVE-2026-19165 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19165 Use after free in Extensions
CVE-2026-19164 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19164 Insufficient validation of untrusted input in Codecs
CVE-2026-19163 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19163 Use after free in Media
CVE-2026-19162 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19162 Out of bounds write in V8
CVE-2026-19161 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19161 Uninitialized Use in Skia
CVE-2026-19160 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19160 Uninitialized Use in Skia
CVE-2026-19159 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19159 Use after free in Views
CVE-2026-19158 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19158 Use after free in Views
CVE-2026-19157 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19157 Out of bounds write in ANGLE
CVE-2026-19156 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19156 Heap buffer overflow in Base
CVE-2026-19155 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19155 Use after free in Payments
CVE-2026-19153 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19153 Insufficient validation of untrusted input in Workers
CVE-2026-19152 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19152 Inappropriate implementation in Navigation
CVE-2026-19151 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19151 Use after free in V8
CVE-2026-19150 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19150 Inappropriate implementation in V8
CVE-2026-19149 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19149 Use after free in Aura
CVE-2026-19148 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19148 Out of bounds write in GPU
CVE-2026-19147 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19147 Use after free in Aura
CVE-2026-19146 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19146 Uninitialized Use in GPU
CVE-2026-19145 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19145 Use after free in Translate
CVE-2026-19144 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19144 Use after free in HTML
CVE-2026-19142 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19142 Use after free in Views
CVE-2026-19140 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19140 Use after free in GPU
CVE-2026-19139 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19139 Race in CredentialProvider
CVE-2026-19138 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19138 Heap buffer overflow in CrashReporting
CVE-2026-19137 ↗Microsoft Edge (Chromium-based)N/A0%CVE-2026-19137 Use after free in WebGL
CVE-2024-26464 ↗cbl2 net-snmp 5.9.4-1N/AOut-of-band
CVE-2024-31745 ↗cbl2 libdwarf 0.9.0-3N/AOut-of-band
CVE-2024-5814 ↗cbl2 mariadb 10.6.9-6N/AOut-of-band0%Unverifed Ciphersuite used on a client-side TLS1.3 Downgrade
CVE-2026-68398 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0N/Appp: defer channel free to an RCU grace period to fix pppol2tp RX UAF
CVE-2026-68413 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0N/Awifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
CVE-2026-68428 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0N/AKVM: x86/mmu: Fix use-after-free on vendor module reload
CVE-2026-61477 ↗azl3 libvirt 10.10.0-2 on Azure Linux 3.0N/ALibvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection
CVE-2026-64655 ↗azl3 gh 2.62.0-20 on Azure Linux 3.0N/AGitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching
CVE-2026-64652 ↗azl3 gh 2.62.0-20 on Azure Linux 3.0N/AGitHub CLI: Partial token disclosure in `gh auth status` output
CVE-2026-54522 ↗azl3 rubygem-msgpack 1.7.2-1 on Azure Linux 3.0N/AOut-of-bandMessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure
CVE-2026-54787 ↗azl3 gh 2.62.0-20 on Azure Linux 3.0N/AOut-of-bandsigstore-go fails to check signature timestamps against a signing key's validity period
CVE-2024-3205 ↗azl3 libyaml 0.2.5-3 on Azure Linux 3.0N/AOut-of-bandRejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The maintainer identified an error in the libyaml fuzzers. It is not possible to reproduce nor exploit the issue.
CVE-2024-36022 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0N/AOut-of-bandRejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-37753 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0N/AOut-of-bandRejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-43022 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0N/AOut-of-bandBluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists
CVE-2024-38620 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0N/AOut-of-bandBluetooth: HCI: Remove HCI_AMP support
CVE-2025-21635 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0N/AOut-of-bandrds: sysctl: rds_tcp_{rcv,snd}buf: avoid using current->nsproxy
CVE-2024-38628 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0N/AOut-of-bandusb: gadget: u_audio: Fix race condition use of controls after free during gadget unbind.

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-59083trackedCVSS 3.7Red Hat JBoss Web Server 7.0 on RHEL 10jws7-tomcat-0:11.0.21-6.redhat_00005.1.el10jws.noarchPatch ↗Advisory ↗
Red HatCVE-2026-59083trackedCVSS 3.7Red Hat JBoss Web Server 7.0.1Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream AUS (v.8.4)firefox-0:140.13.0-1.el8_4.srcPatch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream EUS (v. 10.0)firefox-0:140.13.0-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.9.4)firefox-0:140.13.0-1.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.9.2)firefox-0:140.13.0-1.el9_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-6170CVSS 2.5Red Hat Insights proxy 1.5registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:296963717d1d077fc4a37a323ab0a34843b0b5d3eeaa15af0a5ca07b83dcd2c1_arm64Patch ↗Advisory ↗
Red HatCVE-2025-71072CVSS 2.5Red Hat Enterprise Linux AppStream (v. 10)kernel-64k-debug-debuginfo-0:6.12.0-211.46.1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.9.4)thunderbird-0:140.13.0-1.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream EUS (v. 10.0)thunderbird-0:140.13.0-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream EUS (v.9.6)thunderbird-0:140.13.0-1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream AUS (v.8.6)thunderbird-0:140.13.0-1.el8_6.srcPatch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.8.8)thunderbird-0:140.13.0-1.el8_8.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream AUS (v.8.4)thunderbird-0:140.13.0-1.el8_4.srcPatch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.9.2)thunderbird-0:140.13.0-1.el9_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Hardened Imagesjava-25-openjdk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Enterprise Linux Supplementary EUS (v. 10.0)java-21-ibm-semeru-certified-jdk-1:21.0.12.0.8-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Enterprise Linux Supplementary (v. 8)java-1.8.0-ibm-1:1.8.0.8.70-1.el8_10.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-47059CVSS 3.7Red Hat Hardened Imagesjava-25-openjdk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47059CVSS 3.7Red Hat Enterprise Linux Supplementary EUS (v. 10.0)java-21-ibm-semeru-certified-jdk-1:21.0.12.0.8-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47059CVSS 3.7Red Hat Enterprise Linux Supplementary (v. 8)java-1.8.0-ibm-1:1.8.0.8.70-1.el8_10.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-53434CVSS 3.7Red Hat JBoss Web Server 7.0 on RHEL 10jws7-tomcat-0:11.0.21-6.redhat_00005.1.el10jws.noarchPatch ↗Advisory ↗
Red HatCVE-2026-53434CVSS 3.7Red Hat JBoss Web Server 7.0.1Patch ↗Advisory ↗
Red HatCVE-2026-55276CVSS 2.3Red Hat JBoss Web Server 7.0 on RHEL 10jws7-tomcat-0:11.0.21-6.redhat_00005.1.el10jws.noarchPatch ↗Advisory ↗
Red HatCVE-2026-55276CVSS 2.3Red Hat JBoss Web Server 7.0.1Patch ↗Advisory ↗
Red HatCVE-2026-67316CVSS 3.7Red Hat Hardened Imagesgrafana13-1-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream (v. 8)thunderbird-0:140.13.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Hardened Imagesjava-21-openjdk-portable-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Hardened Imagesjava-21-openjdk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47059CVSS 3.7Red Hat Hardened Imagesjava-21-openjdk-portable-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47059CVSS 3.7Red Hat Hardened Imagesjava-21-openjdk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.13.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-40469CVSS 2.8Red Hat Hardened Imagesgawk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-67316CVSS 3.7Red Hat Hardened Imagesgrafana13-1-main@aarch64Patch ↗Advisory ↗