CYBERSECURITYTRACKER
TRACKING7,931 stories in this site build1,728 vulnerability news stories in this site build
Vulnerabilities

August 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 1 vulnerability with exploitation detected in the wild this month. This defender-focused view covers 6,845 vulnerabilities across 17,509 returned patch records from 5 vendors. Filter the complete month, or browse the static page trail without JavaScript.

17,509all patch recordsClear filters2,377criticalShow these records1Microsoft exploitation detectedShow these records3Microsoft in the Known Exploited Vulnerabilities catalogShow these records14,331tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

My Stack only keeps records whose vendor you have pinned. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 52 of 88 · records 10,201 to 10,400 of 17,509

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-64475 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablevfio/pci: Release the VGA arbiter client on register_device() failure
CVE-2026-64481 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableALSA: hda/cs35l41: Fix firmware load work teardown
CVE-2026-64421 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablemedia: nxp: imx8-isi: Fix use-after-free on remove
CVE-2026-64391 ↗azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableksmbd: use opener credentials for ADS I/O
CVE-2026-64274 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableInput: goodix - clamp the device-reported contact count
CVE-2026-64315 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablecrypto: caam - use print_hex_dump_devel to guard key hex dumps
CVE-2026-64270 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableInput: mms114 - reject an oversized device packet size
CVE-2026-64322 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableudf: validate sparing table length as an entry count, not a byte count
CVE-2026-64385 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablesmb: client: fix double-free in SMB2_ioctl() replay
CVE-2026-64436 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablenet: af_key: initialize alg_key_len for IPComp states
CVE-2026-64435 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableaudit: Fix data races of skb_queue_len() readers on audit_queue
CVE-2026-64296 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableexfat: bound uniname advance in exfat_find_dir_entry()
CVE-2026-64280 ↗azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablefpga: dfl-afu: validate DMA mapping length in afu_dma_map_region()
CVE-2026-64329 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableusb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove
CVE-2026-64440 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablestaging: rtl8723bs: fix OOB write in HT_caps_handler()
CVE-2026-64393 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableksmbd: run set info with opener credentials
CVE-2026-64449 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablestaging: vme_user: bound slave read/write to the kern_buf size
CVE-2026-64456 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablehwrng: virtio: clamp device-reported used.len at copy_data()
CVE-2026-64342 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableUSB: iowarrior: fix use-after-free on disconnect
CVE-2026-64365 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableHID: letsketch: fix UAF on inrange_timer at driver unbind
CVE-2026-64380 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablesmb: client: harden POSIX SID length parsing
CVE-2026-64392 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableksmbd: use opener credentials for delete-on-close
CVE-2026-64389 ↗azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableksmbd: validate NTLMv2 response before updating session key
CVE-2026-64445 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablestaging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()
CVE-2026-64304 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablecrypto: qat - validate RSA CRT component lengths
CVE-2026-64320 ↗azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailablenvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
CVE-2026-64361 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablehfs/hfsplus: fix u32 overflow in check_and_correct_requested_length
CVE-2026-64446 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablestaging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie()
CVE-2026-64437 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL
CVE-2026-64399 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableksmbd: add permission checks for FSCTL_DUPLICATE_EXTENTS_TO_FILE
CVE-2026-64341 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableUSB: iowarrior: fix use-after-free on disconnect race
CVE-2026-64268 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableRDMA/siw: bound Read Response placement to the RREAD length
CVE-2026-64340 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableUSB: legousbtower: fix use-after-free on disconnect race
CVE-2026-64333 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableUSB: serial: digi_acceleport: fix write buffer corruption
CVE-2026-64448 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailablesmb: client: restrict implied bcc[0] exemption to responses without data area
CVE-2026-64395 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableksmbd: require source read access for duplicate extents
CVE-2026-64362 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableHID: lg-g15: cancel pending work on remove to fix a use-after-free
CVE-2026-64343 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableUSB: ldusb: fix use-after-free on disconnect race
CVE-2026-64305 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablecrypto: qat - protect service table iterations with service_lock
CVE-2026-64386 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablesmb: client: fix query_info() replay double-free
CVE-2026-64411 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablenetfilter: ebtables: terminate table name before find_table_lock()
CVE-2026-64273 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableInput: iforce - bound the device-reported force-feedback effect index
CVE-2026-64469 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablebinder: fix UAF in binder_thread_release()
CVE-2026-64266 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablefuse: re-lock request before returning from fuse_ref_folio()
CVE-2026-64246 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablepower: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()
CVE-2026-64403 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableBluetooth: L2CAP: validate option length before reading conf opt value
CVE-2026-66033 ↗azl3 libssh 0.10.6-8 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailablelibssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation
CVE-2026-66035 ↗azl3 nmap 7.95-4 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailablelibssh2 Heap Buffer Overflow via ETM Cipher Negotiation
CVE-2026-64286 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableKVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU
CVE-2026-66032 ↗azl3 nmap 7.95-4 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablelibssh2 Double-Free Heap Corruption via sftp_open()
CVE-2026-64377 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablecpufreq: qcom-cpufreq-hw: Fix possible double free
CVE-2026-66034 ↗azl3 libssh2 1.11.1-4 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablelibssh2 Heap Out-of-Bounds Read via publickey subsystem
CVE-2026-64344 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableUSB: idmouse: fix use-after-free on disconnect race
CVE-2026-64382 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablesmb: client: fix double-free in SMB2_open() replay
CVE-2026-64298 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableNFSv4: include MAY_WRITE in open permission mask for O_TRUNC
CVE-2026-64249 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablefpga: region: fix use-after-free in child_regions_with_firmware()
CVE-2026-64330 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableusb: typec: tcpm: Validate SVID index in svdm_consume_modes()
CVE-2026-64255 ↗azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablewifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers
CVE-2026-64313 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablecrypto: ecc - Fix carry overflow in vli multiplication
CVE-2026-64402 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablecoresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer()
CVE-2026-64210 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablenet/mlx5e: xsk: Fix unlocked writing to ICOSQ
CVE-2026-64379 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablesmb: client: mask server-provided mode to 07777 in modefromsid
CVE-2026-64442 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablestaging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()
CVE-2026-64303 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailablespi: fsl-lpspi: terminate the RX channel on TX prepare failure path
CVE-2026-13321 ↗azl3 bind 9.20.23-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableDNSSEC Validation Bypass via Out-of-Zone NSEC Next Field
CVE-2026-56852 ↗azl3 azurelinux-image-tools 1.5.0-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableInfinite loop on invalid input in golang.org/x/text
CVE-2026-64600 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailable1 mentionsxfs: resample the data fork mapping after cycling ILOCK
CVE-2026-48526 ↗azl3 python-jwt 2.8.0-2 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablePyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed
CVE-2026-34181 ↗azl3 kata-containers 3.32.0.kata0-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablePKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys
CVE-2026-34180 ↗azl3 shim-unsigned-aarch64 16.1-2 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableHeap Buffer Over-read in ASN.1 Content Parsing
CVE-2026-42764 ↗azl3 cloud-hypervisor 51.1.56-1 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableNULL Pointer Dereference in QUIC Server Initial Packet Handling
CVE-2026-9076 ↗azl3 kata-containers 3.32.0.kata0-1 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableOut-of-Bounds Read in CMS Password-Based Decryption
CVE-2026-7383 ↗azl3 cloud-hypervisor 51.1.56-1 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailablePossible Heap Buffer Overflow in ASN.1 Multibyte String Conversion
CVE-2026-34183 ↗azl3 cloud-hypervisor 51.1.56-1 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableUnbounded Memory Growth in the QUIC PATH_CHALLENGE Handler
CVE-2026-45447 ↗azl3 openssl 3.3.7-3 on Azure Linux 3.0ImportantOut-of-band4%Microsoft rating unavailableHeap Use-After-Free in the PKCS7_verify() Function
CVE-2026-45445 ↗azl3 openssl 3.3.7-1 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableAES-OCB IV Ignored on EVP_Cipher() Path
CVE-2026-48864 ↗azl3 libsolv 0.7.28-3 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableLibsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data
CVE-2026-9804 ↗azl3 kubevirt 1.7.1-8 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableKubevirt: kubevirt: vmexport directory symlink escape enables exporter pod file read
CVE-2026-44307 ↗azl3 python-mako 1.2.4-3 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableMako: Path traversal via backslash URI on Windows in TemplateLookup
CVE-2026-43249 ↗azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailable9p/xen: protect xen_9pfs_front_free against concurrent calls
CVE-2026-29168 ↗cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-band1%Microsoft rating unavailableApache HTTP Server: mod_md unrestricted OCSP response
CVE-2026-29169 ↗cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-band2%Microsoft rating unavailableApache HTTP Server: mod_dav_lock indirect lock crash
CVE-2026-24072 ↗cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-band1%Microsoft rating unavailableApache HTTP Server: mod_rewrite elevation of privileges via ap_expr
CVE-2026-34059 ↗cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-band1%Microsoft rating unavailableApache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data()
CVE-2026-23918 ↗cbl2 httpd 2.4.66-1 on CBL Mariner 2.0ImportantOut-of-band50%Microsoft rating unavailable1 mentionsApache HTTP Server: http2: double free and possible RCE on early reset
CVE-2026-43258 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablealpha: fix user-space corruption during memory compaction
CVE-2026-43125 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailabledlm: validate length in dlm_search_rsb_tree
CVE-2026-30656 ↗azl3 fio 3.37-3 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableA NULL pointer dereference vulnerability exists in fio (Flexible I/O Tester) v3.41 when parsing job files containing the fdp_pli option. The callback function str_fdp_pli_cb() does not validate the input pointer and calls strdup() on a NULL value when the option is specified without an argument. This results in a segmentation fault and process crash.
CVE-2026-6846 ↗azl3 gdb 13.2-7 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableBinutils: binutils: arbitrary code execution via malformed xcoff object file processing
CVE-2026-43009 ↗azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablebpf: Fix incorrect pruning due to atomic fetch precision tracking
CVE-2026-31771 ↗azl3 kernel 6.6.137.1-2 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableBluetooth: hci_event: move wake reason storage into validated event handlers
CVE-2026-43042 ↗azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablempls: add seqcount to protect the platform_label{,s} pair
CVE-2026-43049 ↗azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableHID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure
CVE-2026-43048 ↗azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableHID: core: Mitigate potential OOB by removing bogus memset()
CVE-2026-41602 ↗azl3 influxdb 2.7.5-15 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableApache Thrift: Go TFramedTransport uint32 overflow
CVE-2026-34001 ↗cbl2 xorg-x11-server 1.20.10-16 on CBL Mariner 2.0ImportantOut-of-band0%Microsoft rating unavailableXorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and potential memory corruption
CVE-2026-5435 ↗azl3 glibc 2.38-19 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablePotential buffer overflow in ns_sprintrrf TSIG handling path
CVE-2026-31688 ↗azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledriver core: enforce device_lock for driver_match_device()
CVE-2026-31630 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-band0%Microsoft rating unavailablerxrpc: proc: size address buffers for %pISpc output
CVE-2026-31568 ↗azl3 kernel 6.6.130.1-3 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailables390/mm: Add missing secure storage access fixups for donated memory
CVE-2026-35469 ↗azl3 containerd2 0.0.0-1 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableSpdyStream: DOS on CRI
CVE-2026-4732 ↗azl3 libsndfile 1.2.2-4 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableOut-of-bounds Read Overflow in tildearrow/furnace
CVE-2026-4046 ↗cbl2 glibc 2.35-10 on CBL Mariner 2.0ImportantOut-of-band1%Microsoft rating unavailableiconv crash due to assertion failure with untrusted input
CVE-2026-21710 ↗cbl2 nodejs18 18.20.3-12ImportantOut-of-band25%Microsoft rating unavailableA flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a non-array. This exception is thrown synchronously inside a property getter and cannot be intercepted by `error` event listeners, meaning it cannot be handled without wrapping every `req.headersDistinct` access in a `try/catch`. * This vulnerability affects all Node.js HTTP servers on **20.x, 22.x, 24.x, and v25.x**
CVE-2026-1519 ↗cbl2 bind 9.16.50-3 on CBL Mariner 2.0ImportantOut-of-band2%Microsoft rating unavailableExcessive NSEC3 iterations cause high CPU load during insecure delegation validation
CVE-2026-23361 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablePCI: dwc: ep: Flush MSI-X write before unmapping its ATU entry
CVE-2026-33186 ↗cbl2 grpc 1.42.0-11 on CBL Mariner 2.0ImportantOut-of-band2%Microsoft rating unavailablegRPC-Go has an authorization bypass via missing leading slash in :path
CVE-2026-31802 ↗cbl2 tar 1.34-3 on CBL Mariner 2.0ImportantOut-of-band0%Microsoft rating unavailablenode-tar Symlink Path Traversal via Drive-Relative Linkpath
CVE-2026-23240 ↗azl3 kernel 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailabletls: Fix race condition in tls_sw_cancel_work_tx()
CVE-2025-69650 ↗azl3 binutils 2.41-10 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailableGNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service.
CVE-2026-29786 ↗azl3 tar 1.35-2 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablenode-tar: Hardlink Path Traversal via Drive-Relative Linkpath
CVE-2026-0031 ↗cbl2 hyperv-daemons 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-band0%Microsoft rating unavailableIn multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0032 ↗cbl2 hyperv-daemons 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-band0%Microsoft rating unavailableIn multiple functions of mem_protect.c, there is a possible out-of-bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2026-0038 ↗azl3 hyperv-daemons 6.6.126.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableIn multiple functions of mem_protect.c, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2023-53543 ↗cbl2 kernel 5.15.202.1-1 on CBL Mariner 2.0ImportantOut-of-band0%Microsoft rating unavailablevdpa: Add max vqp attr to vdpa_nl_policy for nlattr length check
CVE-2025-69299 ↗azl3 doxygen 1.9.8-2 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableWordPress Oxygen theme <= 6.0.8 - Server Side Request Forgery (SSRF) vulnerability
CVE-2024-58240 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-band0%Microsoft rating unavailabletls: separate no-async decryption request handling from async
CVE-2025-68304 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableBluetooth: hci_core: lookup hci_conn on RX path on protocol side
CVE-2025-68174 ↗azl3 kernel 6.6.119.3-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableamd/amdkfd: enhance kfd process check in switch partition
CVE-2025-44904 ↗cbl2 hdf5 1.14.6-1 on CBL Mariner 2.0ImportantOut-of-band0%Microsoft rating unavailablehdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.
CVE-2025-59775 ↗cbl2 httpd 2.4.65-1 on CBL Mariner 2.0ImportantOut-of-band1%Microsoft rating unavailableApache HTTP Server: NTLM Leakage on Windows through UNC SSRF
CVE-2023-53254 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-band0%Microsoft rating unavailablecacheinfo: Fix shared_cpu_map to handle shared caches at different levels
CVE-2025-38656 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablewifi: iwlwifi: Fix error code in iwl_op_mode_dvm_start()
CVE-2025-40170 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablenet: use dst_dev_rcu() in sk_setup_caps()
CVE-2025-40139 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablesmc: Use __sk_dst_get() and dst_dev_rcu() in in smc_clc_prfx_set().
CVE-2025-61725 ↗cbl2 golang 1.22.7-5 on CBL Mariner 2.0ImportantOut-of-band1%Microsoft rating unavailableExcessive CPU consumption in ParseAddress in net/mail
CVE-2025-40075 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailabletcp_metrics: use dst_dev_net_rcu()
CVE-2025-40074 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableipv4: start using dst_dev_rcu()
CVE-2025-55551 ↗azl3 pytorch 2.2.2-7 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableAn issue in the component torch.linalg.lu of pytorch v2.8.0 allows attackers to cause a Denial of Service (DoS) when performing a slice operation.
CVE-2025-39905 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablenet: phylink: add lock for serializing concurrent pl->phydev writes with resolver
CVE-2025-39901 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablei40e: remove read access to debugfs files
CVE-2025-38728 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablesmb3: fix for slab out of bounds on mount to ksmbd
CVE-2025-38679 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablemedia: venus: Fix OOB read due to missing payload bound check
CVE-2025-38584 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablepadata: Fix pd UAF once and for all
CVE-2025-38585 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablestaging: media: atomisp: Fix stack buffer overflow in gmin_get_var_int()
CVE-2025-37882 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableusb: xhci: Fix isochronous Ring Underrun/Overrun event handling
CVE-2025-4802 ↗cbl2 glibc 2.35-7 on CBL Mariner 2.0ImportantOut-of-band1%Microsoft rating unavailableUntrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
CVE-2025-38250 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailableBluetooth: hci_core: Fix use-after-free in vhci_flush()
CVE-2025-52194 ↗cbl2 libsndfile 1.0.31-3 on CBL Mariner 2.0ImportantOut-of-band1%Microsoft rating unavailableA buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the ircam_read_header function at src/ircam.c:164 during sample rate processing, leading to memory corruption and potential code execution.
CVE-2025-38248 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablebridge: mcast: Fix use-after-free during router port configuration
CVE-2025-37786 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ImportantOut-of-band0%Microsoft rating unavailablenet: dsa: free routing table on probe failure
CVE-2025-37879 ↗azl3 kernel 6.6.92.2-1 on Azure Linux 3.0ImportantOut-of-band1%Microsoft rating unavailable9p/net: fix improper handling of bogus negative read/write replies
CVE-2024-1545 ↗cbl2 mariadb 10.6.9-6ImportantOut-of-band1%Microsoft rating unavailableFault Injection of RSA encryption in WolfCrypt
CVE-2026-54330 ↗azl3 ceph 18.2.2-12 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableCeph RGW SigV4 handler accepts unsigned x-amz-* headers on presigned requests, allowing privilege escalation
CVE-2025-30156 ↗azl3 ceph 18.2.2-12 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableCeph: AES-CBC misuse in CephX and RADOSGW enables authentication bypass and credential forgery

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2024-29180CVSS 7.4Red Hat Discovery 2registry.redhat.io/discovery/discovery-ui-rhel9@sha256:480c69f89b45c714ec13a7901bc8615a2fa3f4622c889cd023d80a6278855a58_arm64Patch ↗Advisory ↗
Red HatCVE-2026-25681CVSS 8.1Red Hat Enterprise Linux AppStream E4S (v.9.2)osbuild-composer-0:76.1-8.el9_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-27136CVSS 8.1Red Hat Enterprise Linux AppStream E4S (v.9.2)osbuild-composer-0:76.1-8.el9_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-27145CVSS 7.5Red Hat Enterprise Linux AppStream E4S (v.9.2)go-toolset-0:1.26.5-1.el9_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-27145CVSS 7.5Cluster Observability Operator 1.5.0registry.redhat.io/cluster-observability-operator/perses-rhel9@sha256:3319c9cc20bd47d7e85925611b16c155607b3131e1a62e599573808d4359c78c_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-28684CVSS 7.1Red Hat AI Inference Server 3.2registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:7424dba120d55743add1b9ddad5290d8a5fbd01eb0e57321c996e562ef8416ed_arm64Patch ↗Advisory ↗
Red HatCVE-2026-31411CVSS 7.1Red Hat Enterprise Linux BaseOS E4S (v.8.8)bpftool-0:4.18.0-477.161.1.el8_8.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-33814CVSS 7.5Red Hat Enterprise Linux AppStream E4S (v.9.2)go-toolset-0:1.26.5-1.el9_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-34734CVSS 7.8Red Hat Hardened Imageshdf5-0:2.2.0-0.1.1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-34982CVSS 8.2Red Hat OpenShift Container Platform 4.14rhcos-aarch64-414.92.202608172040-0Patch ↗Advisory ↗
Red HatCVE-2026-34982CVSS 8.2Red Hat OpenShift Container Platform 4.16rhcos-aarch64-416.94.202608150307-0Patch ↗Advisory ↗
Red HatCVE-2026-34982CVSS 8.2Red Hat OpenShift Container Platform 4.15rhcos-aarch64-415.92.202608180329-0Patch ↗Advisory ↗
Red HatCVE-2026-41178CVSS 7.5Cluster Observability Operator 1.5.0registry.redhat.io/cluster-observability-operator/alertmanager-rhel9@sha256:51e1cee9ccde0bb3b363f59861a97da546215e0c012af6ef533d5e09387cb6ff_amd64Patch ↗Advisory ↗
Red HatCVE-2026-41411CVSS 7.3Red Hat OpenShift Container Platform 4.14rhcos-aarch64-414.92.202608172040-0Patch ↗Advisory ↗
Red HatCVE-2026-41411CVSS 7.3Red Hat OpenShift Container Platform 4.16rhcos-aarch64-416.94.202608150307-0Patch ↗Advisory ↗
Red HatCVE-2026-41411CVSS 7.3Red Hat OpenShift Container Platform 4.15rhcos-aarch64-415.92.202608180329-0Patch ↗Advisory ↗
Red HatCVE-2026-44222CVSS 7.5Red Hat AI Inference Server 3.2registry.redhat.io/rhaiis/vllm-cuda-rhel9@sha256:44224455142130c9594b4361fd21494c88244acb59b242f31ecb66019a5238dd_arm64Patch ↗Advisory ↗
Red HatCVE-2026-44222CVSS 7.5Red Hat AI Inference Server 3.2registry.redhat.io/rhaiis/vllm-rocm-rhel9@sha256:7536efb184e4161d6b8a11477392b93613408c7d68daebb5cbad73b57a985e26_amd64Patch ↗Advisory ↗
Red HatCVE-2026-44740CVSS 7.5Cluster Observability Operator 1.5.0registry.redhat.io/cluster-observability-operator/perses-rhel9-operator@sha256:1d1ee8463e8ec2f5323e6d2ebd1971a39f472f60dc21d155f99a8e12a82a44f3_s390xPatch ↗Advisory ↗
Red HatCVE-2026-44943CVSS 8.6Red Hat Enterprise Linux AppStream EUS (v. 10.0)iscsi-initiator-utils-debuginfo-0:6.2.1.9-22.gita65a472.el10_0.1.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-46483CVSS 7.0Red Hat OpenShift Container Platform 4.14rhcos-aarch64-414.92.202608172040-0Patch ↗Advisory ↗
Red HatCVE-2026-46483CVSS 7.0Red Hat OpenShift Container Platform 4.16rhcos-aarch64-416.94.202608150307-0Patch ↗Advisory ↗
Red HatCVE-2026-46483CVSS 7.0Red Hat OpenShift Container Platform 4.15rhcos-aarch64-415.92.202608180329-0Patch ↗Advisory ↗
Red HatCVE-2026-50193CVSS 7.5Red Hat AI Inference Server 3.2registry.redhat.io/rhaiis/vllm-cuda-rhel9@sha256:44224455142130c9594b4361fd21494c88244acb59b242f31ecb66019a5238dd_arm64Patch ↗Advisory ↗
Red HatCVE-2026-55194CVSS 8.8Red Hat Enterprise Linux AppStream (v. 10)freerdp-2:3.10.3-12.el10_2.10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-55194CVSS 8.8Red Hat Enterprise Linux AppStream (v. 9)freerdp-2:2.11.7-7.el9_8.6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-59868CVSS 7.5Red Hat Discovery 2registry.redhat.io/discovery/discovery-ui-rhel9@sha256:480c69f89b45c714ec13a7901bc8615a2fa3f4622c889cd023d80a6278855a58_arm64Patch ↗Advisory ↗
Red HatCVE-2026-63633CVSS 8.8Red Hat Enterprise Linux AppStream (v. 10)freerdp-2:3.10.3-12.el10_2.10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-73241CVSS 7.5Red Hat Enterprise Linux AppStream (v. 10)freerdp-2:3.10.3-12.el10_2.10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-63383CVSS 7.5Red Hat Hardened Imageslibevent-0:2.1.12-19.1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-63384CVSS 7.5Red Hat Hardened Imageslibevent-0:2.1.12-19.1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-63388CVSS 8.4Red Hat Hardened Imageslibevent-0:2.1.12-19.1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-25681CVSS 8.1Red Hat OpenShift AI 3.4registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:5b32f727afed4fe60f0c1f53d05bc0345e2b02c55c9882de10cb376366686461_arm64Patch ↗Advisory ↗
Red HatCVE-2026-27136CVSS 8.1Red Hat OpenShift AI 3.4registry.redhat.io/rhoai/odh-feast-operator-rhel9@sha256:93103baa91d898da51cdf88c6a5e5c499b0ae6d12e420bb77743cdd06bf45b2f_amd64Patch ↗Advisory ↗
Red HatCVE-2026-33814CVSS 7.5Red Hat OpenShift AI 3.4registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:5b32f727afed4fe60f0c1f53d05bc0345e2b02c55c9882de10cb376366686461_arm64Patch ↗Advisory ↗
Red HatCVE-2026-34993CVSS 7.2Red Hat OpenShift AI 3.4registry.redhat.io/rhoai/odh-llama-stack-core-rhel9@sha256:1458d874cda368ba9e4eda79bc4d9414529a695f361dad677504791824e0f209_arm64Patch ↗Advisory ↗
Red HatCVE-2026-39828CVSS 8.8Red Hat OpenShift AI 3.4registry.redhat.io/rhoai/odh-trainer-rhel9@sha256:017d26624a3a3f0572d15d88967a47cb92f7e192ad9b57732499c71db3f273ec_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-39835CVSS 7.5Red Hat OpenShift AI 3.4registry.redhat.io/rhoai/odh-data-science-pipelines-argo-argoexec-rhel9@sha256:5b32f727afed4fe60f0c1f53d05bc0345e2b02c55c9882de10cb376366686461_arm64Patch ↗Advisory ↗
Red HatCVE-2026-42338CVSS 8.1Red Hat OpenShift AI 3.4registry.redhat.io/rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9@sha256:206b9bc4eb2f30537b9d1f99cc0ebc4926fcb1e936ef6b6a2ffcebd3abdc0bb4_arm64Patch ↗Advisory ↗
Red HatCVE-2026-44292CVSS 7.5Red Hat OpenShift AI 3.4registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:4a475dd6221080671c742651eede4964956caf997fa84f10c1c889b4bb2eb935_amd64Patch ↗Advisory ↗
Red HatCVE-2026-44943CVSS 8.6Red Hat Enterprise Linux AppStream EUS (v.9.6)iscsi-initiator-utils-debuginfo-0:6.2.1.9-1.gita65a472.el9_6.3.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-45292CVSS 7.5Red Hat OpenShift AI 3.4registry.redhat.io/rhoai/odh-kserve-agent-rhel9@sha256:380c89ebd19206b4907a2147c0f9690c825055135d90d5463f45fe08d36b1f71_arm64Patch ↗Advisory ↗
Red HatCVE-2026-45736CVSS 7.5Red Hat OpenShift AI 3.4registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:4a475dd6221080671c742651eede4964956caf997fa84f10c1c889b4bb2eb935_amd64Patch ↗Advisory ↗
Red HatCVE-2026-45740CVSS 7.5Red Hat OpenShift AI 3.4registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:4a475dd6221080671c742651eede4964956caf997fa84f10c1c889b4bb2eb935_amd64Patch ↗Advisory ↗
Red HatCVE-2026-49978CVSS 8.1Red Hat OpenShift AI 3.4registry.redhat.io/rhoai/odh-dashboard-rhel9@sha256:4a475dd6221080671c742651eede4964956caf997fa84f10c1c889b4bb2eb935_amd64Patch ↗Advisory ↗
Red HatCVE-2026-50193CVSS 7.5Red Hat OpenShift AI 3.4registry.redhat.io/rhoai/odh-th06-cpu-torch210-py312-rhel9@sha256:cdd7d9f982c1f8a94dd4aad43e705274aae1bf0942e0442e60c3973f9c198f23_amd64Patch ↗Advisory ↗
Red HatCVE-2026-69243CVSS 7.0Red Hat OpenShift AI 3.4registry.redhat.io/rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9@sha256:368a3a34d5f57726bde442bf02963ecb1724d648e1dfdebe30fbd026c80fa38c_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-8643CVSS 8.0Red Hat OpenShift AI 3.4registry.redhat.io/rhoai/odh-automl-rhel9@sha256:11140a858c6fd3174d63e845f7d0bd451e67d50adc3befbfac57659d6334dfef_amd64Patch ↗Advisory ↗
Red HatCVE-2025-13465CVSS 8.2Red Hat OpenShift Container Platform 4.18registry.redhat.io/openshift4/ose-monitoring-plugin-rhel9@sha256:2bf5b7480b3f1d68ec8d32a65239c99ecdc58dec1442f66c1c15646e48c06212_ppc64lePatch ↗Advisory ↗
Red HatCVE-2025-68121CVSS 7.4Red Hat OpenShift Container Platform 4.14openshift-0:4.14.0-202608131802.p2.g288be6b.assembly.stream.el8.srcPatch ↗Advisory ↗
Red HatCVE-2025-68121CVSS 7.4Red Hat OpenShift Container Platform 4.14registry.redhat.io/openshift4/ose-coredns@sha256:60386814c055520cef9dd6cc417258e766047e47f7af206f00d904c8ee660c57_s390xPatch ↗Advisory ↗
Red HatCVE-2025-68121CVSS 7.4Red Hat OpenShift Container Platform 4.14registry.redhat.io/openshift4/ose-ansible-operator@sha256:04f8da394eaef8c3292b93fe29efe916716687cff4101c229850334dbee39abe_amd64Patch ↗Advisory ↗
Red HatCVE-2025-68121CVSS 7.4Red Hat OpenShift Container Platform 4.16containernetworking-plugins-1:1.4.0-10.rhaos4.16.el8.aarch64Patch ↗Advisory ↗
Red HatCVE-2025-68121CVSS 7.4Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/ose-coredns-rhel9@sha256:3fc3068c4a47599d2f6b46e0c66b072546a36d3fd01844e50dfd9296b86bb441_s390xPatch ↗Advisory ↗
Red HatCVE-2025-68121CVSS 7.4Red Hat OpenShift Container Platform 4.16registry.redhat.io/openshift4/frr-rhel9@sha256:2c8603c74e2dff1fc773c019e917a616c91536f85554856d6e21b797244b2a36_s390xPatch ↗Advisory ↗

Glossary