CYBERSECURITYTRACKER
TRACKING4,568 stories861 vuln stories
Patch Day month

August 2026 vulnerabilities

A defender-focused view of 3,380 vulnerabilities across 6,852 returned patch records from 4 vendors. Filter the month to date, or browse the static page trail without JavaScript.

6,852all patch recordsClear filters243criticalShow these records1Microsoft exploitation detectedShow these records2Microsoft in CISA KEVShow these records1,814tracked hereShow these records

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as “no.” “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An EPSS percentage is the global 30-day exploitation probability in the wild, not specific to you.

Page 33 of 35 · records 6,401–6,600 of 6,852

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2024-46681 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandpktgen: use cpus_read_lock() in pg_net_init()
CVE-2024-46705 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/xe: reset mmio mappings with devm
CVE-2024-46701 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandlibfs: fix infinite directory reads for offset dir
CVE-2024-41014 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandxfs: add bounds checking to xlog_recover_process_data
CVE-2024-44970 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ModerateOut-of-bandnet/mlx5e: SHAMPO, Fix invalid WQ linked list unlink
CVE-2024-49898 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Check null-initialized variables
CVE-2024-42158 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ModerateOut-of-bands390/pkey: Use kfree_sensitive() to fix Coccinelle warnings
CVE-2024-49911 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Add NULL check for function pointer in dcn20_set_output_transfer_func
CVE-2024-46698 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandvideo/aperture: optionally match the device in sysfb_disable()
CVE-2019-11254 ↗azl3 packer 1.9.5-11 on Azure Linux 3.0ModerateOut-of-bandKubernetes API Server denial of service vulnerability from malicious YAML payloads
CVE-2024-46808 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Add missing NULL pointer check within dpcd_extend_address_range
CVE-2024-41023 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ModerateOut-of-bandsched/deadline: Fix task_struct reference leak
CVE-2024-49909 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Add NULL check for function pointer in dcn32_set_output_transfer_func
CVE-2023-52920 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ModerateOut-of-bandbpf: support non-r10 register spill/fill to/from stack in precision tracking
CVE-2024-43824 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandPCI: endpoint: pci-epf-test: Make use of cached 'epc_features' in pci_epf_test_core_init()
CVE-2025-38333 ↗azl3 kernel 6.6.96.1-1 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix to bail out in get_new_segment()
CVE-2025-38097 ↗azl3 kernel 6.6.92.2-2 on Azure Linux 3.0ModerateOut-of-bandespintcp: remove encap socket caching to avoid reference leak
CVE-2025-38127 ↗azl3 kernel 6.6.96.1-1 on Azure Linux 3.0ModerateOut-of-bandice: fix Tx scheduler error handling in XDP callback
CVE-2025-38192 ↗azl3 kernel 6.6.96.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: clear the dst when changing skb protocol
CVE-2025-38334 ↗azl3 kernel 6.6.92.2-2 on Azure Linux 3.0ModerateOut-of-bandx86/sgx: Prevent attempts to reclaim poisoned pages
CVE-2025-4432 ↗azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0ModerateOut-of-bandRing: some aes functions may panic when overflow checking is enabled in ring
CVE-2024-49569 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandnvme-rdma: unquiesce admin_q before destroy it
CVE-2025-22057 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandnet: decrease cached dst counters in dst_release
CVE-2025-37800 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-banddriver core: fix potential NULL pointer dereference in dev_uevent()
CVE-2025-37801 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandspi: spi-imx: Add check for spi_imx_setupxfer()
CVE-2025-37849 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandKVM: arm64: Tear down vGIC on failed vCPU creation
CVE-2025-37852 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdgpu: handle amdgpu_cgs_create_device() errors in amd_powerplay_create()
CVE-2025-37853 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-banddrm/amdkfd: debugfs hang_hws skip GPU with MES
CVE-2025-37878 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandperf/core: Fix WARN_ON(!ctx) in __free_event() for partial init
CVE-2025-37884 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Fix deadlock between rcu_tasks_trace and event_mutex.
CVE-2024-50615 ↗azl3 tinyxml2 9.0.0-2 on Azure Linux 3.0ModerateOut-of-bandTinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.
CVE-2025-21947 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandksmbd: fix type confusion via race condition when using ipc_msg_send_request
CVE-2025-21969 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandBluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd
CVE-2025-21792 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandax25: Fix refcount leak caused by setting SO_BINDTODEVICE sockopt
CVE-2025-21667 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ModerateOut-of-bandiomap: avoid avoid truncating 64-bit offset to 32 bits
CVE-2025-21673 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ModerateOut-of-bandsmb: client: fix double free of TCP_Server_Info::hostname
CVE-2024-47141 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-bandpinmux: Use sequential access to access desc->pinmux data
CVE-2024-47809 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-banddlm: fix possible lkb_resource null dereference
CVE-2024-48875 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-bandbtrfs: don't take dev_replace rwsem on task already holding it
CVE-2024-56665 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-bandbpf,perf: Fix invalid prog_array access in perf_event_detach_bpf_prog
CVE-2024-56703 ↗azl3 kernel 6.6.78.1-3 on Azure Linux 3.0ModerateOut-of-bandipv6: Fix soft lockups in fib6_select_path under high next hop churn
CVE-2024-56719 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ModerateOut-of-bandnet: stmmac: fix TSO DMA API usage causing oops
CVE-2024-50248 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandntfs3: Add bounds checking to mi_enum_attr()
CVE-2024-50256 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandnetfilter: nf_reject_ipv6: fix potential crash in nf_send_reset6()
CVE-2024-50284 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: Fix the missing xa_store error check
CVE-2024-50285 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandksmbd: check outstanding simultaneous SMB operations
CVE-2024-53079 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandmm/thp: fix deferred split unqueue naming and locking
CVE-2024-53091 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandbpf: Add sk_is_inet and IS_ICSK check in tls_sw_has_ctx_tx/rx
CVE-2024-53093 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandnvme-multipath: defer partition scanning
CVE-2024-53094 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandRDMA/siw: Add sendpage_ok() check to disable MSG_SPLICE_PAGES
CVE-2024-53100 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ModerateOut-of-bandnvme: tcp: avoid race between queue_lock lock and destroy
CVE-2024-1543 ↗azl3 mariadb 10.11.6-3 on Azure Linux 3.0ModerateOut-of-bandAES T-Table sub-cache-line leakage
CVE-2024-1544 ↗azl3 mariadb 10.11.6-3 on Azure Linux 3.0ModerateOut-of-bandECDSA nonce bias caused by truncation
CVE-2024-5288 ↗azl3 mariadb 10.11.6-3 on Azure Linux 3.0ModerateOut-of-bandSafe-error attack on TLS 1.3 Protocol
CVE-2024-49978 ↗azl3 kernel 6.6.57.1-2 on Azure Linux 3.0ModerateOut-of-bandgso: fix udp gso fraglist segmentation after pull from frag_list
CVE-2024-49987 ↗azl3 kernel 6.6.57.1-2 on Azure Linux 3.0ModerateOut-of-bandbpftool: Fix undefined behavior in qsort(NULL 0 ...)
CVE-2024-49988 ↗azl3 kernel 6.6.57.1-2 on Azure Linux 3.0ModerateOut-of-bandksmbd: add refcnt to ksmbd_conn struct
CVE-2024-47678 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-bandicmp: change the order of rate limits
CVE-2024-47683 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Skip Recompute DSC Params if no Stream on Link
CVE-2024-47704 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Check link_res->hpo_dp_link_enc before using it
CVE-2024-47728 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-bandbpf: Zero former ARG_PTR_TO_{LONGINT} args in case of error
CVE-2024-49859 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-bandf2fs: fix to check atomic_file in f2fs ioctl interfaces
CVE-2024-49905 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Add null check for 'afb' in amdgpu_dm_plane_handle_cursor_update (v2)
CVE-2024-49912 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ModerateOut-of-banddrm/amd/display: Handle null 'stream_status' in 'planes_changed_for_existing_stream'
CVE-2024-46678 ↗azl3 kernel 6.6.51.1-5 on Azure Linux 3.0ModerateOut-of-bandbonding: change ipsec_lock from spin lock to mutex
CVE-2024-46762 ↗azl3 kernel 6.6.51.1-5 on Azure Linux 3.0ModerateOut-of-bandxen: privcmd: Fix possible access to a freed kirqfd instance
CVE-2024-46765 ↗azl3 kernel 6.6.51.1-5 on Azure Linux 3.0ModerateOut-of-bandice: protect XDP configuration with a mutex
CVE-2024-46803 ↗azl3 kernel 6.6.51.1-5 on Azure Linux 3.0ModerateOut-of-banddrm/amdkfd: Check debug trap enable before write dbg_ev_file
CVE-2024-27005 ↗azl3 hyperv-daemons 6.6.35.1-1 on Azure Linux 3.0ModerateOut-of-bandinterconnect: Don't access req_list while it's being manipulated
CVE-2024-35794 ↗azl3 hyperv-daemons 6.6.35.1-1 on Azure Linux 3.0ModerateOut-of-banddm-raid: really frozen sync_thread during suspend
CVE-2024-35808 ↗azl3 hyperv-daemons 6.6.35.1-1 on Azure Linux 3.0ModerateOut-of-bandmd/dm-raid: don't call md_reap_sync_thread() directly
CVE-2024-42067 ↗azl3 kernel 6.6.43.1-7 on Azure Linux 3.0ModerateOut-of-bandbpf: Take return from set_memory_rox() into account with bpf_jit_binary_lock_ro()
CVE-2024-1151 ↗azl3 hyperv-daemons 6.6.22.1-2 on Azure Linux 3.0ModerateOut-of-bandKernel: stack overflow problem in open vswitch kernel module leading to dos
CVE-2024-36009 ↗azl3 hyperv-daemons 6.6.35.1-1 on Azure Linux 3.0ModerateOut-of-bandax25: Fix netdev refcount issue
CVE-2020-29509 ↗azl3 golang 1.24.3-1 on Azure Linux 3.0ModerateOut-of-bandThe encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
CVE-2020-29511 ↗azl3 golang 1.24.3-1 on Azure Linux 3.0ModerateOut-of-bandThe encoding/xml package in Go (all versions) does not correctly preserve the semantics of element namespace prefixes during tokenization round-trips which allows an attacker to craft inputs that behave in conflicting ways during different stages of processing in affected downstream applications.
CVE-2021-20227 ↗sqlite-3.34.1-1.cm1.x86_64.rpm on CBL Mariner 1.0 x64ModerateOut-of-bandA flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.
CVE-2020-15358 ↗cm1 mysql 8.0.26-1 on CBL Mariner 1.0ModerateOut-of-bandIn SQLite before 3.32.3 select.c mishandles query-flattener optimization leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation.
CVE-2026-74567 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band0%keys: fix out-of-bounds read in keyring_get_key_chunk()
CVE-2026-74475 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band0%vxlan: use neigh_ha_snapshot() in route_shortcircuit()
CVE-2026-74495 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band1%igbvf: Fix leak in TX DMA error cleanup
CVE-2026-74564 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-band0%netfilter: xt_hashlimit: validate hashtable supports XT_HASHLIMIT_RATE_MATCH
CVE-2026-68433 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowOut-of-band0%libceph: bound get_version reply decode to front len
CVE-2026-68446 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowOut-of-band0%drm/vmwgfx: Validate vmw_surface_metadata::array_size
CVE-2026-64532 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0LowOut-of-band0%
CVE-2025-46686 ↗cbl2 redis 6.2.18-3LowOut-of-band0%Redis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated user. This occurs because the server allocates memory for the command arguments of every bulk, even when the command is skipped because of insufficient permissions. NOTE: this is disputed by the Supplier because abuse of the commands network protocol is not a violation of the Redis Security Model.
CVE-2026-40556 ↗cbl2 nano 6.0-3LowOut-of-bandInsecure Directory Permissions in GNU nano Leading to Privilege Abuse
CVE-2025-11840 ↗cbl2 binutils 2.37-19LowOut-of-band0%GNU Binutils ldmisc.c vfinfo out-of-bounds
CVE-2025-2913 ↗cbl2 hdf5 1.14.4-1LowOut-of-band0%HDF5 H5FL.c H5FL__blk_gc_list use after free
CVE-2026-74711 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandhwmon: (pmbus) Fix type confusion in notification logic
CVE-2026-74659 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandnet: bridge: mrp: fix uninitialised bytes on the wire
CVE-2026-74733 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandgpio: pca953x: fix pca953x_irq_bus_sync_unlock regmap lock
CVE-2026-74603 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandptp: ocp: Fix board ID over-read
CVE-2026-74655 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandserial: qcom-geni: fix TX DMA buffer flush
CVE-2026-74658 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandfutex: Prevent robust futex exit race some more
CVE-2026-74676 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandvt: add permission check for KDSKBMETA ioctl
CVE-2026-74671 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandima: fix out-of-bounds read in xattr_verify()
CVE-2026-74679 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandusb: gadget: f_ncm: Use unsigned int for ndp_index
CVE-2026-74719 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandnet/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler()
CVE-2026-74673 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandInput: evdev - fix information leak in evdev_pass_values()
CVE-2026-74680 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandusb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()
CVE-2026-74678 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandnet: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup()
CVE-2026-74464 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandnet: openvswitch: fix skb leak on flow key update failure during ct
CVE-2026-72495 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandRDMA/bnxt_re: Avoid repeated requests to allocate WC pages
CVE-2026-72438 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandmd/raid10: fix writes_pending and barrier reference leaks on discard failures
CVE-2026-74268 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandtcp: clear sock_ops cb flags before force-closing a child socket
CVE-2026-72315 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandsmb: client: fix busy dentry warning on unmount after DIO
CVE-2026-74338 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandbpf: Reject sleepable BPF_LSM_CGROUP programs at load time
CVE-2026-74456 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandcan: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error
CVE-2026-74544 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandnet/sched: cls_u32: validate offshift to prevent shift-out-of-bounds
CVE-2026-73071 ↗azl3 vim 9.2.0782-1 on Azure Linux 3.0LowOut-of-bandVim: Use-after-free in JSON Decoding
CVE-2026-74577 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandnet: mpls: initialize rtm_tos in mpls_getroute()
CVE-2026-73283 ↗azl3 openssh 9.8p1-9 on Azure Linux 3.0LowOut-of-bandIn sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
CVE-2026-74317 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandixgbe: do not configure xps for XDP queues
CVE-2026-74525 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandnet: sxgbe: free TX rings on RX allocation failure
CVE-2026-61712 ↗azl3 moby-engine 25.0.3-19 on Azure Linux 3.0LowOut-of-bandBuildKit: Possible runtime DoS via unbounded group parsing
CVE-2026-60589 ↗azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0LowOut-of-bandVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vect
CVE-2026-74579 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandnetfilter: nft_payload: fix mask build for partial field offload
CVE-2026-14666 ↗azl3 postgresql 16.14-1 on Azure Linux 3.0LowOut-of-bandPostgreSQL row security caching disregards role modifications
CVE-2026-6469 ↗azl3 postgresql 16.14-1 on Azure Linux 3.0LowOut-of-bandPostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership
CVE-2026-14673 ↗azl3 postgresql 16.14-1 on Azure Linux 3.0LowOut-of-bandPostgreSQL amcheck does not clear untrusted search path
CVE-2026-19411 ↗azl3 shim-unsigned-aarch64 16.1-2 on Azure Linux 3.0LowOut-of-bandShim/dp.c library: null-pointer dereference in is_removable_media_path() when devicepathtostr() returns null
CVE-2026-18503 ↗azl3 python3 3.12.9-14 on Azure Linux 3.0LowOut-of-bandSuper-linear CPU usage for unbounded input to csv.Sniffer.sniff()
CVE-2026-68429 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowOut-of-banddrm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()
CVE-2026-68450 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowOut-of-bandbtrfs: free mapping node on duplicate reloc root insert
CVE-2026-73281 ↗azl3 openssh 9.8p1-9 on Azure Linux 3.0LowOut-of-bandIn ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
CVE-2026-72712 ↗azl3 nmap 7.95-4 on Azure Linux 3.0LowOut-of-bandNmap 7.99 Denial of Service via Zero-Length TCP Option Packet
CVE-2026-6368 ↗azl3 glibc 2.38-20 on Azure Linux 3.0LowOut-of-bandwordexp with WRDE_APPEND can return or use invalid memory

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-59083trackedCVSS 3.7Red Hat JBoss Web Server 7.0 on RHEL 10jws7-tomcat-0:11.0.21-6.redhat_00005.1.el10jws.noarchPatch ↗Advisory ↗
Red HatCVE-2026-59083trackedCVSS 3.7Red Hat JBoss Web Server 7.0.1Patch ↗Advisory ↗
Red HatCVE-2026-53584CVSS 3.5Red Hat Hardened Imageslibgit2-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2025-6170CVSS 2.5Red Hat Update Infrastructure 5registry.redhat.io/rhui5/cds-kubernetes-tp-rhel9@sha256:6b19042f120e63358cf2cebd8c53af9e75a5a34a7cfde642c3a88a5ddadf94a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-2297CVSS 3.3Red Hat Update Infrastructure 5registry.redhat.io/rhui5/installer-tp-rhel9@sha256:9a9560142c4c4023279a47bdb144a7f4c2f3e7c96fcac281c29f93b4b21ef235_amd64Patch ↗Advisory ↗
Red HatCVE-2026-35386CVSS 3.6Red Hat Update Infrastructure 5registry.redhat.io/rhui5/installer-tp-rhel9@sha256:9a9560142c4c4023279a47bdb144a7f4c2f3e7c96fcac281c29f93b4b21ef235_amd64Patch ↗Advisory ↗
Red HatCVE-2026-35387CVSS 3.1Red Hat Update Infrastructure 5registry.redhat.io/rhui5/installer-tp-rhel9@sha256:9a9560142c4c4023279a47bdb144a7f4c2f3e7c96fcac281c29f93b4b21ef235_amd64Patch ↗Advisory ↗
Red HatCVE-2026-35388CVSS 2.2Red Hat Update Infrastructure 5registry.redhat.io/rhui5/installer-tp-rhel9@sha256:9a9560142c4c4023279a47bdb144a7f4c2f3e7c96fcac281c29f93b4b21ef235_amd64Patch ↗Advisory ↗
Red HatCVE-2026-3832CVSS 3.7Red Hat Update Infrastructure 5registry.redhat.io/rhui5/cds-kubernetes-tp-rhel9@sha256:6b19042f120e63358cf2cebd8c53af9e75a5a34a7cfde642c3a88a5ddadf94a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-45446CVSS 3.7Red Hat Update Infrastructure 5registry.redhat.io/rhui5/cds-kubernetes-tp-rhel9@sha256:6b19042f120e63358cf2cebd8c53af9e75a5a34a7cfde642c3a88a5ddadf94a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-5419CVSS 3.7Red Hat Update Infrastructure 5registry.redhat.io/rhui5/cds-kubernetes-tp-rhel9@sha256:6b19042f120e63358cf2cebd8c53af9e75a5a34a7cfde642c3a88a5ddadf94a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-55654CVSS 3.7Red Hat Update Infrastructure 5registry.redhat.io/rhui5/installer-tp-rhel9@sha256:9a9560142c4c4023279a47bdb144a7f4c2f3e7c96fcac281c29f93b4b21ef235_amd64Patch ↗Advisory ↗
Red HatCVE-2026-74976CVSS 3.4Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.14.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-74976CVSS 3.4Red Hat Enterprise Linux AppStream (v. 8)firefox-0:140.14.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-74976CVSS 3.4Red Hat Enterprise Linux AppStream (v. 10)firefox-0:140.14.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-74983CVSS 3.4Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.14.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-74983CVSS 3.4Red Hat Enterprise Linux AppStream (v. 8)firefox-0:140.14.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-74983CVSS 3.4Red Hat Enterprise Linux AppStream (v. 10)firefox-0:140.14.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18503CVSS 2.8Red Hat Hardened Imagespython3-12-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-3479CVSS 3.3Red Hat Hardened Imagespython3-12-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Hardened Imagesjava-21-openjdk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18503CVSS 2.8Red Hat Hardened Imagespython3-11-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-3479CVSS 3.3Red Hat Hardened Imagespython3-11-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Enterprise Linux AppStream (v. 8)java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7OPENJDK ELS 11.0.32.1Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7OPENJDK ELS 11.0.32.1Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Hardened Imagesjava-25-openjdk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18503CVSS 2.8Red Hat Hardened Imagespython3-10-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18739CVSS 2.5Red Hat Hardened Imagespopt-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60190CVSS 2.2Red Hat Enterprise Linux AppStream (v. 8)mecab-0:0.996-2.module+el8.10.0+23550+bd321b9a.aarch64::mysql:8.4Patch ↗Advisory ↗
Red HatCVE-2026-60190CVSS 2.2Red Hat Enterprise Linux AppStream (v. 9)mecab-0:0.996-3.module+el9.8.0+24348+9b27f387.4.aarch64::mysql:8.4Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Enterprise Linux Server (v. 7 ELS)java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el7_9.i686Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 8u504Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 8u504Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat OpenJDK 11 ELS for RHEL 7java-11-openjdk-1:11.0.32.1.1-1.el7_9.s390xPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Enterprise Linux AppStream (v. 8)java-17-openjdk-1:17.0.20.1.1-1.1.el8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 17.0.20.1Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 17.0.20.1Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Enterprise Linux AppStream EUS (v. 10.0)java-21-openjdk-1:21.0.12.1.1-1.1.el10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 21.0.12.1Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 21.0.12.1Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Enterprise Linux AppStream (v. 10)java-25-openjdk-1:25.0.4.1.1-1.1.el10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 25.0.4.1Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Hardened Imagesjava-21-openjdk-portable-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Hardened Imagesjava-25-openjdk-portable-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-61081CVSS 2.7Red Hat Enterprise Linux AppStream (v. 8)mecab-0:0.996-2.module+el8.10.0+23550+bd321b9a.aarch64::mysql:8.4Patch ↗Advisory ↗
Red HatCVE-2026-61081CVSS 2.7Red Hat Enterprise Linux AppStream (v. 9)mecab-0:0.996-3.module+el9.8.0+24348+9b27f387.4.aarch64::mysql:8.4Patch ↗Advisory ↗
Red HatCVE-2026-61096CVSS 2.9Red Hat Enterprise Linux AppStream (v. 8)mecab-0:0.996-2.module+el8.10.0+23550+bd321b9a.aarch64::mysql:8.4Patch ↗Advisory ↗
Red HatCVE-2026-61096CVSS 2.9Red Hat Enterprise Linux AppStream (v. 9)mecab-0:0.996-3.module+el9.8.0+24348+9b27f387.4.aarch64::mysql:8.4Patch ↗Advisory ↗
Red HatCVE-2026-11525CVSS 3.7Red Hat Openshift Data Foundation 4.18registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:21b851833c425cd0638fa0d97672b30481fe6196a38817955500f10f3516acaa_arm64Patch ↗Advisory ↗
Red HatCVE-2026-22036CVSS 3.7Red Hat Openshift Data Foundation 4.18registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:21b851833c425cd0638fa0d97672b30481fe6196a38817955500f10f3516acaa_arm64Patch ↗Advisory ↗
Red HatCVE-2026-60190CVSS 2.2Red Hat Enterprise Linux AppStream (v. 10)mysql8.4-0:8.4.11-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-61081CVSS 2.7Red Hat Enterprise Linux AppStream (v. 10)mysql8.4-0:8.4.11-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-61096CVSS 2.9Red Hat Enterprise Linux AppStream (v. 10)mysql8.4-0:8.4.11-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6733CVSS 3.7Red Hat Openshift Data Foundation 4.18registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:21b851833c425cd0638fa0d97672b30481fe6196a38817955500f10f3516acaa_arm64Patch ↗Advisory ↗
Red HatCVE-2026-59842CVSS 3.7Red Hat Enterprise Linux AppStream (v. 10)libssh-debuginfo-0:0.12.0-3.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-59846CVSS 3.9Red Hat Enterprise Linux AppStream (v. 10)libssh-debuginfo-0:0.12.0-3.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-59849CVSS 3.1Red Hat Enterprise Linux AppStream (v. 10)libssh-debuginfo-0:0.12.0-3.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18503CVSS 2.8Red Hat Hardened Imagespython3-14-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18503CVSS 2.8Red Hat Hardened Imagespython3-13-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33551CVSS 3.5Red Hat OpenStack Platform 16.2openstack-keystone-1:16.0.3-2.20260616134936.9d699a7.el8ost.noarchPatch ↗Advisory ↗
Red HatCVE-2026-66484CVSS 3.3Red Hat Hardened Imagescpio-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6879CVSS 2.2Red Hat Hardened Imagespython3-14-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6879CVSS 2.2Red Hat Hardened Imagespython3-13-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream AUS (v.8.4)firefox-0:140.13.0-1.el8_4.srcPatch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream EUS (v. 10.0)firefox-0:140.13.0-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.9.4)firefox-0:140.13.0-1.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.9.2)firefox-0:140.13.0-1.el9_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux Server (v. 7 ELS)firefox-0:140.13.0-1.el7_9.ppc64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream EUS (v.9.6)firefox-0:140.13.0-1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream AUS (v.8.6)firefox-0:140.13.0-1.el8_6.srcPatch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.8.8)firefox-0:140.13.0-1.el8_8.ppc64lePatch ↗Advisory ↗