CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Patch Day month

August 2026 vulnerabilities

Microsoft reports 1 vulnerability with exploitation detected in the wild this month. This defender-focused view covers 4,090 vulnerabilities across 9,232 returned patch records from 4 vendors. Filter the complete month, or browse the static page trail without JavaScript.

9,232all patch recordsClear filters433criticalShow these records1Microsoft exploitation detectedShow these records2Microsoft in the Known Exploited Vulnerabilities catalogShow these records2,812tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as “no.” “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 44 of 47 · records 8,601 to 8,800 of 9,232

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-72438 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablemd/raid10: fix writes_pending and barrier reference leaks on discard failures
CVE-2026-74268 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailabletcp: clear sock_ops cb flags before force-closing a child socket
CVE-2026-72315 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablesmb: client: fix busy dentry warning on unmount after DIO
CVE-2026-74338 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablebpf: Reject sleepable BPF_LSM_CGROUP programs at load time
CVE-2026-74456 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablecan: peak_usb: peak_usb_start(): fix double free of transfer buffer on URB submit error
CVE-2026-74544 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablenet/sched: cls_u32: validate offshift to prevent shift-out-of-bounds
CVE-2026-73071 ↗azl3 vim 9.2.0782-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableVim: Use-after-free in JSON Decoding
CVE-2026-74577 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablenet: mpls: initialize rtm_tos in mpls_getroute()
CVE-2026-73283 ↗azl3 openssh 9.8p1-9 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableIn sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
CVE-2026-74317 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableixgbe: do not configure xps for XDP queues
CVE-2026-74525 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablenet: sxgbe: free TX rings on RX allocation failure
CVE-2026-61712 ↗azl3 moby-engine 25.0.3-19 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableBuildKit: Possible runtime DoS via unbounded group parsing
CVE-2026-60589 ↗azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vect
CVE-2026-74579 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nft_payload: fix mask build for partial field offload
CVE-2026-14666 ↗azl3 postgresql 16.14-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablePostgreSQL row security caching disregards role modifications
CVE-2026-6469 ↗azl3 postgresql 16.14-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablePostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership
CVE-2026-14673 ↗azl3 postgresql 16.14-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablePostgreSQL amcheck does not clear untrusted search path
CVE-2026-19411 ↗azl3 shim-unsigned-aarch64 16.1-2 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableShim/dp.c library: null-pointer dereference in is_removable_media_path() when devicepathtostr() returns null
CVE-2026-18503 ↗azl3 python3 3.12.9-14 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableSuper-linear CPU usage for unbounded input to csv.Sniffer.sniff()
CVE-2026-68429 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailabledrm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()
CVE-2026-68450 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablebtrfs: free mapping node on duplicate reloc root insert
CVE-2026-73281 ↗azl3 openssh 9.8p1-9 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableIn ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
CVE-2026-72712 ↗azl3 nmap 7.95-4 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableNmap 7.99 Denial of Service via Zero-Length TCP Option Packet
CVE-2026-6368 ↗azl3 glibc 2.38-20 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablewordexp with WRDE_APPEND can return or use invalid memory
CVE-2026-68304 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablewifi: brcmfmac: fix 802.1X-SHA256 call trace warning
CVE-2026-68229 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablemedia: cedrus: skip invalid H.264 reference list entries
CVE-2026-68209 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablemedia: sun4i-csi: Return queued buffers on start_streaming() failure
CVE-2026-68117 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailabletipc: clear sock->sk on the failed-insert path in tipc_sk_create()
CVE-2026-68376 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablesctp: fix auth_hmacs array size in struct sctp_cookie
CVE-2026-68269 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailabledrm/i915/gem: Add missing nospec on parallel submit slot
CVE-2026-68301 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablenet: hsr: fix memory leak on slave unregistration by removing synced VLANs
CVE-2026-68107 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailabledrm/amdgpu/vcn4: avoid rereading IB param length
CVE-2026-68248 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailabledrm/i915: Return NULL on error in active_instance
CVE-2026-68309 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablewifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()
CVE-2026-68226 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablemedia: cx23885: add ioremap return check and cleanup
CVE-2026-68279 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailabledrm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
CVE-2026-68417 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailableRDMA/siw: publish QP after initialization
CVE-2026-68422 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablebtrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()
CVE-2026-68280 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailabledrm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
CVE-2026-68413 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablewifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
CVE-2026-68277 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailabledrm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
CVE-2026-68220 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablemedia: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe
CVE-2026-68234 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailabledrm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
CVE-2026-68403 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablewifi: brcmfmac: initialize SDIO data work before cleanup
CVE-2026-68355 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablewifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get()
CVE-2026-68312 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablecifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths
CVE-2026-68238 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailabledrm/amdgpu: Release VFCT ACPI table reference
CVE-2026-68302 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailableamt: re-read skb header pointers after every pull
CVE-2026-68256 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailabledrm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference
CVE-2026-68288 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablenet: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD
CVE-2026-68171 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablearm64: syscall: Ensure saved x0 is kept in-sync with tracer updates
CVE-2026-68363 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablewifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request
CVE-2026-68244 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailabledrm/i915/gem: Do not leak siblings[] on proto context error
CVE-2026-61477 ↗azl3 libvirt 10.10.0-2 on Azure Linux 3.0LowNot availableMicrosoft rating unavailableLibvirt: libvirt: newline injection in network xml dns txt/srv fields allows dnsmasq config directive injection
CVE-2026-64655 ↗azl3 gh 2.62.0-20 on Azure Linux 3.0LowNot availableMicrosoft rating unavailableGitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching
CVE-2026-64652 ↗azl3 gh 2.62.0-20 on Azure Linux 3.0LowNot availableMicrosoft rating unavailableGitHub CLI: Partial token disclosure in `gh auth status` output
CVE-2024-21243 ↗azl3 mysql 8.0.41-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Telemetry). Supported versions that are affected are 8.4.2 and prior and 9.0.1 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 2.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).
CVE-2025-21546 ↗azl3 mysql 8.0.41-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).
CVE-2026-64571 ↗azl3 kernel 6.6.145.2-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablewifi: p54: validate RX frame length in p54_rx_eeprom_readback()
CVE-2024-21000 ↗azl3 mysql 8.0.41-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).
CVE-2024-21244 ↗azl3 mysql 8.0.41-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailable
CVE-2026-18839 ↗azl3 rsync 3.4.3-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablePopt-devel: popt-static: size_t underflow in singleoptionhelp
CVE-2026-18739 ↗azl3 popt 1.19-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablePopt-devel: popt-static: off-by-one in poptstuffargs
CVE-2026-19023 ↗azl3 hdf5 1.14.6-4 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableHDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length String Datasets
CVE-2026-58039 ↗azl3 nodejs 24.17.0-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailable
CVE-2026-56847 ↗azl3 nodejs 24.17.0-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailable
CVE-2026-6879 ↗azl3 tensorflow 2.16.1-11 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailable
CVE-2026-15037 ↗azl3 qtbase 6.6.3-5 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableXML injection vulnerability in QDom comment, CDATA and processing-instruction serialization
CVE-2026-64549 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableBluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()
CVE-2026-64546 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailabledrm/edid: fix OOB read in drm_parse_tiled_block()
CVE-2026-64512 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableACPI: CPPC: Suppress UBSAN warning caused by field misuse
CVE-2026-47059 ↗azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 8u491, 8u491-perf, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1; Oracle GraalVM for JDK: 17.0.19 and 21.0.11; Oracle GraalVM Enterprise Edition: 21.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java san
CVE-2026-59846 ↗azl3 libssh 0.10.6-8 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableLibssh: libssh: information disclosure via proxycommand %r username expansion
CVE-2026-16517 ↗azl3 libarchive 3.7.7-6 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableLibarchive: libarchive: signed integer overflow in archive_write_zip_header
CVE-2026-56392 ↗azl3 coreutils 9.4-7 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableHeap-based Buffer Overflow in GNU coreutils
CVE-2026-42770 ↗azl3 openssl 3.3.7-3 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableFFC-DH Peer Validation Uses Attacker-Supplied q
CVE-2026-42768 ↗azl3 openssl 3.3.7-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableMulti-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()
CVE-2026-46044 ↗azl3 kernel 6.6.139.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableipmi:ssif: Clean up kthread on errors
CVE-2026-45893 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableapparmor: Fix & Optimize table creation from possibly unaligned memory
CVE-2026-43969 ↗azl3 rabbitmq-server 3.13.7-3 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableCookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1
CVE-2026-3832 ↗cbl2 gnutls 3.7.11-6 on CBL Mariner 2.0LowOut-of-bandNot availableMicrosoft rating unavailableGnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response
CVE-2026-34743 ↗azl3 xz 5.4.4-2 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableXZ Utils: Buffer overflow in lzma_index_append()
CVE-2026-35388 ↗cbl2 openssh 8.9p1-9 on CBL Mariner 2.0LowOut-of-bandNot availableMicrosoft rating unavailableOpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
CVE-2026-3633 ↗azl3 libsoup 3.4.4-12 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableLibsoup: libsoup: header and http request injection via crlf injection
CVE-2026-3632 ↗azl3 libsoup 3.4.4-12 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableLibsoup: libsoup: http smuggling and server-side request forgery via malformed hostnames
CVE-2026-3634 ↗cbl2 libsoup 3.0.4-12 on CBL Mariner 2.0LowOut-of-bandNot availableMicrosoft rating unavailableLibsoup: libsoup: http header injection and response splitting via crlf injection in content-type header
CVE-2026-0989 ↗cbl2 libxml2 2.10.4-9 on CBL Mariner 2.0LowOut-of-bandNot availableMicrosoft rating unavailableLibxml2: unbounded relaxng include recursion leading to stack overflow
CVE-2025-13837 ↗cbl2 python3 3.9.19-16 on CBL Mariner 2.0LowOut-of-bandNot availableMicrosoft rating unavailableOut-of-memory when loading Plist
CVE-2023-53012 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0LowOut-of-bandNot availableMicrosoft rating unavailablethermal: core: call put_device() only after device_register() fails
CVE-2024-36920 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0LowOut-of-bandNot availableMicrosoft rating unavailablescsi: mpi3mr: Avoid memcpy field-spanning write WARNING
CVE-2025-46394 ↗azl3 busybox 1.36.1-14 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableIn tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
CVE-2024-58251 ↗azl3 busybox 1.36.1-17 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableIn netstat in BusyBox through 1.37.0, local users can launch of network application with an argv[0] containing an ANSI terminal escape sequence, leading to a denial of service (terminal locked up) when netstat is used by a victim.
CVE-2024-7598 ↗azl3 kubernetes 1.30.10-9 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableNetwork restriction bypass via race condition during namespace termination
CVE-2025-7069 ↗cbl2 hdf5 1.14.4-1 on CBL Mariner 2.0LowOut-of-bandNot availableMicrosoft rating unavailableHDF5 H5FSsection.c H5FS__sect_link_size heap-based overflow
CVE-2025-1180 ↗cbl2 gdb 11.2-6 on CBL Mariner 2.0LowOut-of-bandNot availableMicrosoft rating unavailableGNU Binutils ld elf-eh-frame.c _bfd_elf_write_section_eh_frame memory corruption
CVE-2025-1150 ↗azl3 binutils 2.41-7 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableGNU Binutils ld libbfd.c bfd_malloc memory leak
CVE-2025-29477 ↗cbl2 fluent-bit 3.0.6-2 on CBL Mariner 2.0LowOut-of-bandNot availableMicrosoft rating unavailableAn issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the function consume_event.
CVE-2025-29478 ↗cbl2 fluent-bit 3.0.6-2 on CBL Mariner 2.0LowOut-of-bandNot availableMicrosoft rating unavailableAn issue in fluent-bit v.3.7.2 allows a local attacker to cause a denial of service via the cfl_list_size in cfl_list.h:165.
CVE-2025-2912 ↗cbl2 hdf5 1.14.4-1 on CBL Mariner 2.0LowOut-of-bandNot availableMicrosoft rating unavailableHDF5 H5Omessage.c H5O_msg_flush heap-based overflow
CVE-2025-2923 ↗azl3 hdf5 1.14.4.3-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableHDF5 H5Fint.c H5F_addr_encode_len heap-based overflow
CVE-2024-42155 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailables390/pkey: Wipe copies of protected- and secure-keys
CVE-2025-29923 ↗azl3 telegraf 1.31.0-10 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablego-redis allows potential out of order responses when `CLIENT SETINFO` times out during connection establishment
CVE-2024-50211 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableudf: refactor inode_bmap() to handle error
CVE-2024-47738 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablewifi: mac80211: don't use rate mask for offchannel TX either
CVE-2026-78891 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2026-78891 Buffer overflow in WebRTC
CVE-2026-78892 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2026-78892 Incorrect authorization in Chromoting
CVE-2026-78893 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2026-78893 Information leak in QUIC
CVE-2026-78894 ↗Microsoft Edge (Chromium-based)N/AOut-of-band0%Microsoft rating unavailableChromium: CVE-2026-78894 Race condition in Payments

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2026-18503CVSS 2.8Red Hat Hardened Imagespython3-12-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-3479CVSS 3.3Red Hat Hardened Imagespython3-12-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Hardened Imagesjava-21-openjdk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-14673CVSS 3.8Red Hat Hardened Imagespostgresql17-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18503CVSS 2.8Red Hat Hardened Imagespython3-11-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-3479CVSS 3.3Red Hat Hardened Imagespython3-11-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Enterprise Linux AppStream (v. 8)java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7OPENJDK ELS 11.0.32.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7OPENJDK ELS 11.0.32.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Hardened Imagesjava-25-openjdk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18503CVSS 2.8Red Hat Hardened Imagespython3-10-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18739CVSS 2.5Red Hat Hardened Imagespopt-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18743CVSS 2.5Red Hat Hardened Imagespopt-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60190CVSS 2.2Red Hat Enterprise Linux AppStream (v. 8)mecab-0:0.996-2.module+el8.10.0+23550+bd321b9a.aarch64::mysql:8.4Patch ↗Advisory ↗
Red HatCVE-2026-60190CVSS 2.2Red Hat Enterprise Linux AppStream (v. 9)mecab-0:0.996-3.module+el9.8.0+24348+9b27f387.4.aarch64::mysql:8.4Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Enterprise Linux Server (v. 7 ELS)java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el7_9.i686Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 8u504Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 8u504Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat OpenJDK 11 ELS for RHEL 7java-11-openjdk-1:11.0.32.1.1-1.el7_9.s390xPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Enterprise Linux AppStream (v. 8)java-17-openjdk-1:17.0.20.1.1-1.1.el8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 17.0.20.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 17.0.20.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Enterprise Linux AppStream EUS (v. 10.0)java-21-openjdk-1:21.0.12.1.1-1.1.el10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 21.0.12.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 21.0.12.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Enterprise Linux AppStream (v. 10)java-25-openjdk-1:25.0.4.1.1-1.1.el10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 25.0.4.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Hardened Imagesjava-21-openjdk-portable-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Hardened Imagesjava-25-openjdk-portable-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-61081CVSS 2.7Red Hat Enterprise Linux AppStream (v. 8)mecab-0:0.996-2.module+el8.10.0+23550+bd321b9a.aarch64::mysql:8.4Patch ↗Advisory ↗
Red HatCVE-2026-61081CVSS 2.7Red Hat Enterprise Linux AppStream (v. 9)mecab-0:0.996-3.module+el9.8.0+24348+9b27f387.4.aarch64::mysql:8.4Patch ↗Advisory ↗
Red HatCVE-2026-61096CVSS 2.9Red Hat Enterprise Linux AppStream (v. 8)mecab-0:0.996-2.module+el8.10.0+23550+bd321b9a.aarch64::mysql:8.4Patch ↗Advisory ↗
Red HatCVE-2026-61096CVSS 2.9Red Hat Enterprise Linux AppStream (v. 9)mecab-0:0.996-3.module+el9.8.0+24348+9b27f387.4.aarch64::mysql:8.4Patch ↗Advisory ↗
Red HatCVE-2026-11525CVSS 3.7Red Hat Openshift Data Foundation 4.18registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:21b851833c425cd0638fa0d97672b30481fe6196a38817955500f10f3516acaa_arm64Patch ↗Advisory ↗
Red HatCVE-2026-22036CVSS 3.7Red Hat Openshift Data Foundation 4.18registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:21b851833c425cd0638fa0d97672b30481fe6196a38817955500f10f3516acaa_arm64Patch ↗Advisory ↗
Red HatCVE-2026-60190CVSS 2.2Red Hat Enterprise Linux AppStream (v. 10)mysql8.4-0:8.4.11-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-61081CVSS 2.7Red Hat Enterprise Linux AppStream (v. 10)mysql8.4-0:8.4.11-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-61096CVSS 2.9Red Hat Enterprise Linux AppStream (v. 10)mysql8.4-0:8.4.11-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-65183CVSS 2.5Red Hat Hardened Imagestomcat11-main@noarchPatch ↗Advisory ↗
Red HatCVE-2026-66422CVSS 2.7Red Hat Hardened Imagestomcat11-main@noarchPatch ↗Advisory ↗
Red HatCVE-2026-6733CVSS 3.7Red Hat Openshift Data Foundation 4.18registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:21b851833c425cd0638fa0d97672b30481fe6196a38817955500f10f3516acaa_arm64Patch ↗Advisory ↗
Red HatCVE-2026-59842CVSS 3.7Red Hat Enterprise Linux AppStream (v. 10)libssh-debuginfo-0:0.12.0-3.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-59846CVSS 3.9Red Hat Enterprise Linux AppStream (v. 10)libssh-debuginfo-0:0.12.0-3.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-59849CVSS 3.1Red Hat Enterprise Linux AppStream (v. 10)libssh-debuginfo-0:0.12.0-3.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-14673CVSS 3.8Red Hat Hardened Imagespostgresql18-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18503CVSS 2.8Red Hat Hardened Imagespython3-14-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18503CVSS 2.8Red Hat Hardened Imagespython3-13-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33551CVSS 3.5Red Hat OpenStack Platform 16.2openstack-keystone-1:16.0.3-2.20260616134936.9d699a7.el8ost.noarchPatch ↗Advisory ↗
Red HatCVE-2026-66484CVSS 3.3Red Hat Hardened Imagescpio-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6879CVSS 2.2Red Hat Hardened Imagespython3-14-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6879CVSS 2.2Red Hat Hardened Imagespython3-13-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream AUS (v.8.4)firefox-0:140.13.0-1.el8_4.srcPatch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream EUS (v. 10.0)firefox-0:140.13.0-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.9.4)firefox-0:140.13.0-1.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.9.2)firefox-0:140.13.0-1.el9_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux Server (v. 7 ELS)firefox-0:140.13.0-1.el7_9.ppc64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream EUS (v.9.6)firefox-0:140.13.0-1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream AUS (v.8.6)firefox-0:140.13.0-1.el8_6.srcPatch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.8.8)firefox-0:140.13.0-1.el8_8.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-55654CVSS 3.7Red Hat Update Infrastructure 5registry.redhat.io/rhui5/installer-rhel9@sha256:cc0ad7b03c50a4a04058b17aa815c86b8ff06496b2b57db6dbea650415c7f362_amd64Patch ↗Advisory ↗
Red HatCVE-2026-85008CVSS 3.7Red Hat Hardened Imagesnodejs26-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-85008CVSS 3.7Red Hat Hardened Imagesnodejs24-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2025-6170CVSS 2.5Red Hat Insights proxy 1.5registry.redhat.io/insights-proxy/insights-proxy-container-rhel9@sha256:296963717d1d077fc4a37a323ab0a34843b0b5d3eeaa15af0a5ca07b83dcd2c1_arm64Patch ↗Advisory ↗
Red HatCVE-2025-71072CVSS 2.5Red Hat Enterprise Linux AppStream (v. 10)kernel-64k-debug-debuginfo-0:6.12.0-211.46.1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.9.4)thunderbird-0:140.13.0-1.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream EUS (v. 10.0)thunderbird-0:140.13.0-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream EUS (v.9.6)thunderbird-0:140.13.0-1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream AUS (v.8.6)thunderbird-0:140.13.0-1.el8_6.srcPatch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.8.8)thunderbird-0:140.13.0-1.el8_8.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream AUS (v.8.4)thunderbird-0:140.13.0-1.el8_4.srcPatch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.9.2)thunderbird-0:140.13.0-1.el9_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Hardened Imagesjava-25-openjdk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Enterprise Linux Supplementary EUS (v. 10.0)java-21-ibm-semeru-certified-jdk-1:21.0.12.0.8-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Enterprise Linux Supplementary (v. 8)java-1.8.0-ibm-1:1.8.0.8.70-1.el8_10.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-47059CVSS 3.7Red Hat Hardened Imagesjava-25-openjdk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47059CVSS 3.7Red Hat Enterprise Linux Supplementary EUS (v. 10.0)java-21-ibm-semeru-certified-jdk-1:21.0.12.0.8-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47059CVSS 3.7Red Hat Enterprise Linux Supplementary (v. 8)java-1.8.0-ibm-1:1.8.0.8.70-1.el8_10.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-53434CVSS 3.7Red Hat JBoss Web Server 7.0 on RHEL 10jws7-tomcat-0:11.0.21-6.redhat_00005.1.el10jws.noarchPatch ↗Advisory ↗
Red HatCVE-2026-53434CVSS 3.7Red Hat JBoss Web Server 7.0.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-55276CVSS 2.3Red Hat JBoss Web Server 7.0 on RHEL 10jws7-tomcat-0:11.0.21-6.redhat_00005.1.el10jws.noarchPatch ↗Advisory ↗
Red HatCVE-2026-55276CVSS 2.3Red Hat JBoss Web Server 7.0.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-67316CVSS 3.7Red Hat Hardened Imagesgrafana13-1-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream (v. 8)thunderbird-0:140.13.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Hardened Imagesjava-21-openjdk-portable-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47010CVSS 3.7Red Hat Hardened Imagesjava-21-openjdk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47059CVSS 3.7Red Hat Hardened Imagesjava-21-openjdk-portable-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-47059CVSS 3.7Red Hat Hardened Imagesjava-21-openjdk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405CVSS 3.4Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.13.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-40469CVSS 2.8Red Hat Hardened Imagesgawk-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-67316CVSS 3.7Red Hat Hardened Imagesgrafana13-1-main@aarch64Patch ↗Advisory ↗

Glossary