CYBERSECURITYTRACKER
TRACKING7,931 stories in this site build1,728 vulnerability news stories in this site build
Vulnerabilities

August 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 1 vulnerability with exploitation detected in the wild this month. This defender-focused view covers 6,845 vulnerabilities across 17,509 returned patch records from 5 vendors. Filter the complete month, or browse the static page trail without JavaScript.

17,509all patch recordsClear filters2,377criticalShow these records1Microsoft exploitation detectedShow these records3Microsoft in the Known Exploited Vulnerabilities catalogShow these records14,331tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

My Stack only keeps records whose vendor you have pinned. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 57 of 88 · records 11,201 to 11,400 of 17,509

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-64514 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableuserfaultfd: gate must_wait writability check on pte_present()
CVE-2026-64479 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()
CVE-2026-64347 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableusb: gadget: composite: fix dead empty check in the USB_DT_OTG handler
CVE-2026-64513 ↗azl3 kernel 6.6.145.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableKVM: x86: Unconditionally recompute CR8 intercept on PPR update
CVE-2026-64359 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers
CVE-2026-64508 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablebpf: Support for hardening against JIT spraying
CVE-2026-64483 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableALSA: firewire: isight: bound the sample count to the packet payload
CVE-2026-64503 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableiio: accel: kxsd9: fix runtime PM imbalance on write_raw() error
CVE-2026-64337 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableusb: mtu3: unmap request DMA on queue failure
CVE-2026-64376 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablefirmware_loader: fix device reference leak in firmware_upload_register()
CVE-2026-64504 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableiio: accel: bmc150: clamp the device-reported FIFO frame count
CVE-2026-64419 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show()
CVE-2026-64476 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablevfio/pci: Latch disable_idle_d3 per device
CVE-2026-64358 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemedia: mtk-jpeg: cancel workqueue on release for supported platforms only
CVE-2026-64505 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableusb: gadget: function: rndis: add length check for header
CVE-2026-64316 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablecrypto: caam - use print_hex_dump_devel to guard key hex dumps
CVE-2026-64336 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableUSB: serial: keyspan_pda: fix information leak
CVE-2026-64495 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableiio: gyro: bmg160: bail out when bandwidth/filter is not in table
CVE-2026-64405 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableBluetooth: hci_conn: Fix null ptr deref in hci_abort_conn()
CVE-2026-64471 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableBluetooth: btusb: fix use-after-free on registration failure
CVE-2026-64301 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableregulator: scmi: fix of_node refcount leak in scmi_regulator_probe()
CVE-2026-64254 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableNTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR
CVE-2026-64252 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableMIPS: DEC: Prevent initial console buffer from landing in XKPHYS
CVE-2026-64455 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableUSB: chaoskey: Fix slab-use-after-free in chaoskey_release()
CVE-2026-64334 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableUSB: serial: digi_acceleport: fix hard lockup on disconnect
CVE-2026-64212 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablewifi: iwlwifi: mld: don't dereference a pointer before NULL checking it
CVE-2026-64213 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablehwmon: (lm90) Add lock protection to lm90_alert
CVE-2026-64294 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemm: do file ownership checks with the proper mount idmap
CVE-2025-21752 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablebtrfs: don't use btrfs_set_item_key_safe on RAID stripe-extents
CVE-2026-43298 ↗azl3 kernel 6.6.138.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: Skip vcn poison irq release on VF
CVE-2026-43318 ↗azl3 kernel 6.6.141.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: fix sync handling in amdgpu_dma_buf_move_notify
CVE-2026-41907 ↗azl3 uuid 1.6.2-51 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableuuid: Missing buffer bounds check in `v3`/`v5`/`v6` when `buf` is provided
CVE-2026-23377 ↗azl3 kernel 6.6.134.1-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableice: change XDP RxQ frag_size from DMA write length to xdp.frame_sz
CVE-2026-27623 ↗azl3 valkey 8.0.7-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableValkey has Pre-Authentication DOS from malformed RESP request
CVE-2025-69648 ↗cbl2 binutils 2.37-20 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableGNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.
CVE-2025-69651 ↗azl3 binutils 2.41-10 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableGNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service.
CVE-2025-68121 ↗azl3 golang 1.26.0-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableUnexpected session resumption in crypto/tls
CVE-2026-23214 ↗azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablebtrfs: reject new transactions if the fs is fully read-only
CVE-2025-71225 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemd: suspend array while updating raid_disks via sysfs
CVE-2026-23213 ↗azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/pm: Disable MMIO access during SMU Mode 1 reset
CVE-2025-71228 ↗azl3 kernel 6.6.121.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableLoongArch: Set correct protection_map[] for VM_NONE/VM_SHARED
CVE-2025-71109 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableMIPS: ftrace: Fix memory corruption when kernel is located beyond 32 bits
CVE-2025-68188 ↗azl3 kernel 6.6.119.3-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabletcp: use dst_dev_rcu() in tcp_fastopen_active_disable_ofo_check()
CVE-2025-68190 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu/atom: Check kcalloc() for WS buffer in amdgpu_atom_execute_table_locked()
CVE-2025-68224 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablescsi: core: Fix a regression triggered by scsi_host_busy()
CVE-2024-26800 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailabletls: fix use-after-free on failed backlog decryption
CVE-2025-60876 ↗azl3 busybox 1.36.1-19 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableBusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/query), allowing the request line to be split and attacker-controlled headers to be injected. To preserve the HTTP/1.1 request-line shape METHOD SP request-target SP HTTP/1.1, a raw space (0x20) in the request-target must also be rejected (clients should use %20).
CVE-2025-40102 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableKVM: arm64: Prevent access to vCPU events before init
CVE-2025-40057 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableptp: Add a upper bound on max_vclocks
CVE-2025-40065 ↗azl3 kernel 6.6.117.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableRISC-V: KVM: Write hgatp register with valid mode bits
CVE-2025-40039 ↗cbl2 kernel 5.15.200.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableksmbd: Fix race condition in RPC handle list access
CVE-2025-40003 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenet: mscc: ocelot: Fix use-after-free caused by cyclic delayed work
CVE-2022-48744 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenet/mlx5e: Avoid field-overflowing memcpy()
CVE-2024-42861 ↗cbl2 linuxptp 3.1.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableAn issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to the time synchronization function
CVE-2024-45773 ↗azl3 thrift 0.15.0-5 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableA use-after-free vulnerability involving upgradeToRocket requests can cause the application to crash or potentially result in code execution or other undesirable effects. This issue affects Facebook Thrift prior to v2024.09.09.00.
CVE-2023-50230 ↗azl3 bluez 5.63-6 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableBlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2023-5366 ↗cbl2 openvswitch 2.17.9-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailableOpenvswitch don't match packets on nd_target field
CVE-2022-42969 ↗azl3 python-py 1.11.0-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableThe py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled. Note: This has been disputed by multiple third parties as not being reproduceable and they argue this is not a valid vulnerability.
CVE-2019-9192 ↗azl3 smartmontools 7.4-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableIn the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion
CVE-2018-20225 ↗azl3 python-pip 24.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableAn issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely
CVE-2016-2568 ↗azl3 polkit 123-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablepkexec, when used with --user nonpriv, allows local users to escape to the parent session
CVE-2025-39746 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablewifi: ath10k: shutdown driver when hardware is unreliable
CVE-2024-36921 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablewifi: iwlwifi: mvm: guard against invalid STA ID on removal
CVE-2025-21693 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemm: zswap: properly synchronize freeing resources during CPU hotunplug
CVE-2024-26914 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: fix incorrect mpc_combine array size
CVE-2025-21786 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableworkqueue: Put the pwq after detaching the rescuer from the pool
CVE-2025-38096 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablewifi: iwlwifi: don't warn when if there is a FW error
CVE-2025-38140 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledm: limit swapping tables for devices with zone write plugs
CVE-2025-38162 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenetfilter: nft_set_pipapo: prevent overflow in lookup table allocation
CVE-2025-21927 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()
CVE-2025-37807 ↗azl3 kernel 6.6.112.1-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablebpf: Fix kmemleak warning for percpu hashmap
CVE-2025-38041 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableclk: sunxi-ng: h616: Reparent GPU clock during frequency changes
CVE-2025-21985 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Fix out-of-bound accesses
CVE-2025-22121 ↗azl3 kernel 6.6.104.2-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all()
CVE-2025-38264 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablenvme-tcp: sanitize request list handling
CVE-2023-52624 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Wake DMCUB before executing GPINT commands
CVE-2024-42118 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Do not return negative stream id for array
CVE-2025-38449 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledrm/gem: Acquire references on GEM handles for framebuffers
CVE-2024-50217 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablebtrfs: fix use-after-free of block device file in __btrfs_free_extra_devids()
CVE-2024-53133 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Handle dml allocation failure to avoid crash
CVE-2025-22113 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableext4: avoid journaling sb update on error if journal is destroying
CVE-2025-38660 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailable[ceph] parse_longname(): strrchr() expects NUL-terminated string
CVE-2025-38408 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablegenirq/irq_sim: Initialize work context pointers properly
CVE-2024-35862 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablesmb: client: fix potential UAF in smb2_is_network_name_deleted()
CVE-2024-26672 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: Fix variable 'mca_funcs' dereferenced before NULL check in 'amdgpu_mca_smu_get_mca_entry()'
CVE-2023-52586 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledrm/msm/dpu: Add mutex lock in control vblank irq
CVE-2024-35864 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablesmb: client: fix potential UAF in smb2_is_valid_lease_break()
CVE-2025-38311 ↗azl3 kernel 6.6.96.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableiavf: get rid of the crit lock
CVE-2024-57982 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablexfrm: state: fix out-of-bounds read during lookup
CVE-2024-50067 ↗azl3 kernel 6.6.64.2-9 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableuprobe: avoid out-of-bounds memory access of fetching args
CVE-2024-35937 ↗cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0ImportantOut-of-bandNot availableMicrosoft rating unavailablewifi: cfg80211: check A-MSDU format more carefully
CVE-2025-21714 ↗azl3 kernel 6.6.96.2-2 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableRDMA/mlx5: Fix implicit ODP use after free
CVE-2025-38080 ↗azl3 kernel 6.6.96.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledrm/amd/display: Increase block_sequence array size
CVE-2025-37795 ↗Azure Linux 3.0 ARMImportantOut-of-bandNot availableMicrosoft rating unavailableRejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-57798 ↗azl3 kernel 6.6.76.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabledrm/dp_mst: Ensure mst_primary pointer is valid in drm_dp_mst_handle_up_req()
CVE-2024-50073 ↗azl3 kernel 6.6.64.2-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailabletty: n_gsm: Fix use-after-free in gsm_cleanup_mux
CVE-2024-2881 ↗azl3 mariadb 10.11.6-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableFault Injection of EdDSA signature in WolfCrypt
CVE-2024-50228 ↗azl3 kernel 6.6.57.1-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableRejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-49967 ↗azl3 kernel 6.6.51.1-5 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableRejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-47745 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablemm: call the security_mmap_file() LSM hook in remap_file_pages()
CVE-2024-49861 ↗azl3 kernel 6.6.56.1-5 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablebpf: Fix helper writes to read-only maps
CVE-2024-50061 ↗azl3 kernel 6.6.57.1-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablei3c: master: cdns: Fix use after free vulnerability in cdns_i3c_master Driver Due to Race Condition
CVE-2023-38325 ↗azl3 python-cryptography 3.3.2-5 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableThe cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
CVE-2024-34251 ↗azl3 fluent-bit 3.1.9-4 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableAn out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the "block_type_get_arity" function in core/iwasm/interpreter/wasm.h.
CVE-2023-0567 ↗azl3 php 8.3.19-1 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailablepassword_verify() always returns true for some invalid hashes
CVE-2022-38725 ↗azl3 syslog-ng 4.3.1-3 on Azure Linux 3.0ImportantOut-of-bandNot availableMicrosoft rating unavailableAn integer overflow in the RFC3164 parser in One Identity syslog-ng 3.0 through 3.37 allows remote attackers to cause a Denial of Service via crafted syslog input that is mishandled by the tcp or network function. syslog-ng Premium Edition 7.0.30 and syslog-ng Store Box 6.10.0 are also affected.
CVE-2021-33560 ↗cm1 libgcrypt 1.8.7-2 on CBL Mariner 1.0ImportantOut-of-bandNot availableMicrosoft rating unavailableLibgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm and the window size is not chosen appropriately. This for example affects use of ElGamal in OpenPGP.
CVE-2019-6706 ↗cm1 lua 5.3.5-8 on CBL Mariner 1.0ImportantOut-of-bandNot availableMicrosoft rating unavailableLua 5.3.5 has a use-after-free in lua_upvaluejoin in lapi.c. For example a crash outcome might be achieved by an attacker who is able to trigger a debug.upvaluejoin call in which the arguments have certain relationships.
CVE-2026-82250 ↗azl3 rust 1.90.0-10 on Azure Linux 3.0ModerateOut-of-band0%Microsoft rating unavailablegitoxide gix-packetline before 0.21.5 Denial of Service
CVE-2026-37236 ↗azl3 cert-manager 1.12.15-11 on Azure Linux 3.0ModerateOut-of-band0%Microsoft rating unavailablegrpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The application processes the X-HTTP-Method-Override header in ServeMux.ServeHTTP without restricting allowed methods. When a POST request with Content-Type application/x-www-form-urlencoded includes this header, the request method is rewritten to an arbitrary attacker-supplied value before routing. This allows bypassing method-based access controls enforced by upstream proxies or WAFs.

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
Red HatCVE-2025-40026trackedCVSS 5.5Red Hat OpenShift Container Platform 4.14rhcos-aarch64-414.92.202608172040-0Patch ↗Advisory ↗
Red HatCVE-2025-40026trackedCVSS 5.5Red Hat OpenShift Container Platform 4.16rhcos-aarch64-416.94.202608150307-0Patch ↗Advisory ↗
Red HatCVE-2025-40026trackedCVSS 5.5Red Hat OpenShift Container Platform 4.15rhcos-aarch64-415.92.202608180329-0Patch ↗Advisory ↗
SuseCVE-2026-10004trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:148.0.7778.215-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-10018trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:148.0.7778.215-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-10937trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:149.0.7827.155-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-10938trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:149.0.7827.155-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-10992trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:149.0.7827.155-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-10993trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:149.0.7827.155-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-10996trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:149.0.7827.155-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-10997trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:149.0.7827.155-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-10999trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:149.0.7827.155-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-11001trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:149.0.7827.155-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-11653trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:149.0.7827.155-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-11658trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:149.0.7827.155-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-11666trackedCVSS 5.4openSUSE Leap 16.0chromedriver-0:149.0.7827.155-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-13795trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:150.0.7871.186-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-13984trackedCVSS 4.3openSUSE Leap 16.0chromedriver-0:150.0.7871.186-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-13985trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:150.0.7871.186-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-13989trackedCVSS 5.3openSUSE Leap 16.0chromedriver-0:150.0.7871.186-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-14089trackedCVSS 4.3openSUSE Leap 16.0chromedriver-0:150.0.7871.186-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-14105trackedCVSS 4.3openSUSE Leap 16.0chromedriver-0:150.0.7871.186-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-14110trackedCVSS 4.3openSUSE Leap 16.0chromedriver-0:150.0.7871.186-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-14116trackedCVSS 4.3openSUSE Leap 16.0chromedriver-0:150.0.7871.186-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-14118trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:150.0.7871.186-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-14127trackedCVSS 4.3openSUSE Leap 16.0chromedriver-0:150.0.7871.186-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-14130trackedCVSS 4.3openSUSE Leap 16.0chromedriver-0:150.0.7871.186-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-14131trackedCVSS 5.4openSUSE Leap 16.0chromedriver-0:150.0.7871.186-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-14132trackedCVSS 5.4openSUSE Leap 16.0chromedriver-0:150.0.7871.186-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-14133trackedCVSS 4.2openSUSE Leap 16.0chromedriver-0:150.0.7871.186-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-14135trackedCVSS 5.4openSUSE Leap 16.0chromedriver-0:150.0.7871.186-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-14142trackedCVSS 5.4openSUSE Leap 16.0chromedriver-0:150.0.7871.186-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-14150trackedCVSS 5.4openSUSE Leap 16.0chromedriver-0:150.0.7871.186-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-14156trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:150.0.7871.186-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-14396trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:150.0.7871.186-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-15928trackedCVSS 5.4SUSE Liberty Linux 9xmlrpc-c-0:1.51.0-16.el9_6.1.i686no patch linkAdvisory ↗
SuseCVE-2026-15928trackedCVSS 5.4SUSE Liberty Linux 9xmlrpc-c-0:1.51.0-17.el9_8.i686no patch linkAdvisory ↗
Red HatCVE-2026-25087trackedCVSS 5.3Red Hat AI Inference Server 3.2registry.redhat.io/rhaiis/model-opt-cuda-rhel9@sha256:7424dba120d55743add1b9ddad5290d8a5fbd01eb0e57321c996e562ef8416ed_arm64Patch ↗Advisory ↗
SuseCVE-2026-3063trackedCVSS 5.4openSUSE Leap 16.0chromedriver-0:145.0.7632.159-bp160.1.1.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-32281trackedCVSS 5.9Cluster Observability Operator 1.5.0registry.redhat.io/cluster-observability-operator/perses-rhel9@sha256:3319c9cc20bd47d7e85925611b16c155607b3131e1a62e599573808d4359c78c_ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-35469trackedCVSS 6.5Cluster Observability Operator 1.5.0registry.redhat.io/cluster-observability-operator/cluster-observability-rhel9-operator@sha256:1c7533751b55047dd1aa209676359b00dc4cc1471321017d817bb930136e23f4_arm64Patch ↗Advisory ↗
SuseCVE-2026-38753trackedCVSS 5.3SUSE Linux Enterprise High Performance Computing 12 SP5busybox-0:1.35.0-10.9.1.x86_64no patch linkAdvisory ↗
SuseCVE-2026-38754trackedCVSS 5.1SUSE Linux Enterprise High Performance Computing 12 SP5busybox-0:1.35.0-10.9.1.x86_64no patch linkAdvisory ↗
SuseCVE-2026-3930trackedCVSS 5.3openSUSE Leap 16.0chromedriver-0:146.0.7680.177-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-3934trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:146.0.7680.177-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-3935trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:146.0.7680.177-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-3937trackedCVSS 6.5openSUSE Leap 16.0chromedriver-0:146.0.7680.177-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-3938trackedCVSS 4.3openSUSE Leap 16.0chromedriver-0:146.0.7680.177-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-3939trackedCVSS 5.3openSUSE Leap 16.0chromedriver-0:146.0.7680.177-bp160.1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-3940trackedCVSS 5.3openSUSE Leap 16.0chromedriver-0:146.0.7680.177-bp160.1.1.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-42501trackedCVSS 5.3Red Hat Enterprise Linux AppStream E4S (v.9.2)go-toolset-0:1.26.5-1.el9_2.aarch64Patch ↗Advisory ↗
SuseCVE-2026-43116trackedCVSS 5.5SUSE Liberty Linux 7 LTSSbpftool-0:3.10.0-1160.159.1.el7.x86_64no patch linkAdvisory ↗
SuseCVE-2026-48749trackedmoderate (Suse rating)openSUSE Tumbleweedincus-0:7.4-1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-48750trackedmoderate (Suse rating)openSUSE Tumbleweedincus-0:7.4-1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-48751trackedmoderate (Suse rating)openSUSE Tumbleweedincus-0:7.4-1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-48752trackedmoderate (Suse rating)openSUSE Tumbleweedincus-0:7.4-1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-48753trackedmoderate (Suse rating)openSUSE Tumbleweedincus-0:7.4-1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-48755trackedmoderate (Suse rating)openSUSE Tumbleweedincus-0:7.4-1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-48769trackedmoderate (Suse rating)openSUSE Tumbleweedincus-0:7.4-1.1.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-53059trackedCVSS 6.3Red Hat Enterprise Linux Server (v. 7 ELS)bpftool-0:3.10.0-1160.159.1.el7.ppc64Patch ↗Advisory ↗
Red HatCVE-2026-54371trackedCVSS 6.3Red Hat Discovery 2registry.redhat.io/discovery/discovery-server-rhel9@sha256:5efae8059c9c15454abac947b8482412686d60aaf5c104557d463e8282e340af_amd64Patch ↗Advisory ↗
Red HatCVE-2026-5450trackedCVSS 5.0Red Hat OpenShift Container Platform 4.16rhcos-aarch64-416.94.202608150307-0Patch ↗Advisory ↗
SuseCVE-2026-54874trackedCVSS 5.3SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOSlibopenssl-3-devel-0:3.0.8-150500.5.75.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-54874trackedCVSS 5.3SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOSlibopenssl-1_1-devel-0:1.1.1l-150500.17.63.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-54874trackedCVSS 5.3SUSE Linux Enterprise Server 15 SP6-LTSSlibopenssl-1_1-devel-0:1.1.1w-150600.5.38.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-55621trackedmoderate (Suse rating)openSUSE Tumbleweedincus-0:7.4-1.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-55622trackedmoderate (Suse rating)openSUSE Tumbleweedincus-0:7.4-1.1.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-56434trackedCVSS 6.5Red Hat Discovery 2registry.redhat.io/discovery/discovery-ui-rhel9@sha256:480c69f89b45c714ec13a7901bc8615a2fa3f4622c889cd023d80a6278855a58_arm64Patch ↗Advisory ↗
SuseCVE-2026-58014trackedCVSS 4.4SUSE Liberty Linux 8glib2-0:2.56.4-177.el8_10.i686no patch linkAdvisory ↗
SuseCVE-2026-5890trackedCVSS 5.3openSUSE Leap 16.0chromedriver-0:147.0.7727.137-bp160.1.1.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-66032trackedCVSS 6.5Red Hat Enterprise Linux Server (v. 7 ELS)libssh2-0:1.8.0-4.el7_9.2.i686Patch ↗Advisory ↗
Red HatCVE-2026-66034trackedCVSS 5.9Red Hat Enterprise Linux Server (v. 7 ELS)libssh2-0:1.8.0-4.el7_9.2.i686Patch ↗Advisory ↗
Red HatCVE-2026-6653trackedCVSS 5.9Red Hat Enterprise Linux AppStream (v. 9)libxml2-debuginfo-0:2.9.13-14.el9_8.4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6653trackedCVSS 5.9Red Hat Discovery 2registry.redhat.io/discovery/discovery-server-rhel9@sha256:5efae8059c9c15454abac947b8482412686d60aaf5c104557d463e8282e340af_amd64Patch ↗Advisory ↗
SuseCVE-2026-6653trackedCVSS 5.5SUSE Liberty Linux 9libxml2-0:2.9.13-14.el9_8.4.i686no patch linkAdvisory ↗
Red HatCVE-2026-67288trackedCVSS 5.3Red Hat Enterprise Linux AppStream (v. 10)freerdp-2:3.10.3-12.el10_2.10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-67288trackedCVSS 5.3Red Hat Enterprise Linux AppStream (v. 9)freerdp-2:2.11.7-7.el9_8.6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-67289trackedCVSS 5.0Red Hat Enterprise Linux AppStream AUS (v.8.6)freerdp-2:2.2.0-7.el8_6.11.srcPatch ↗Advisory ↗
Red HatCVE-2026-67289trackedCVSS 5.0Red Hat Enterprise Linux AppStream E4S (v.8.8)freerdp-2:2.2.0-12.el8_8.10.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-67291trackedCVSS 6.5Red Hat Enterprise Linux AppStream (v. 10)freerdp-2:3.10.3-12.el10_2.10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-67291trackedCVSS 6.5Red Hat Enterprise Linux AppStream (v. 9)freerdp-2:2.11.7-7.el9_8.6.aarch64Patch ↗Advisory ↗
SuseCVE-2026-67291trackedCVSS 6.5SUSE Liberty Linux 10freerdp-2:3.10.3-12.el10_2.10.x86_64no patch linkAdvisory ↗
SuseCVE-2026-67291trackedCVSS 6.5SUSE Liberty Linux 9freerdp-2:2.11.7-7.el9_8.6.x86_64no patch linkAdvisory ↗
Red HatCVE-2026-67296trackedCVSS 6.5Red Hat Enterprise Linux AppStream (v. 10)freerdp-2:3.10.3-12.el10_2.10.aarch64Patch ↗Advisory ↗
SuseCVE-2026-67296trackedCVSS 5.9SUSE Liberty Linux 10freerdp-2:3.10.3-12.el10_2.10.x86_64no patch linkAdvisory ↗
Red HatCVE-2026-67297trackedCVSS 6.5Red Hat Enterprise Linux AppStream (v. 10)freerdp-2:3.10.3-12.el10_2.10.aarch64Patch ↗Advisory ↗
SuseCVE-2026-67297trackedCVSS 5.3SUSE Liberty Linux 10freerdp-2:3.10.3-12.el10_2.10.x86_64no patch linkAdvisory ↗
Red HatCVE-2026-67299trackedCVSS 6.5Red Hat Enterprise Linux AppStream AUS (v.8.6)freerdp-2:2.2.0-7.el8_6.11.srcPatch ↗Advisory ↗
Red HatCVE-2026-67299trackedCVSS 6.5Red Hat Enterprise Linux AppStream E4S (v.8.8)freerdp-2:2.2.0-12.el8_8.10.ppc64lePatch ↗Advisory ↗
SuseCVE-2026-67301trackedCVSS 6.5SUSE Liberty Linux 10freerdp-2:3.10.3-12.el10_2.10.x86_64no patch linkAdvisory ↗

Glossary