CYBERSECURITYTRACKER
TRACKING7,931 stories in this site build1,728 vulnerability news stories in this site build
Vulnerabilities

August 2026 vulnerabilities

Browse this month's returned vendor patches and exploitation signals, with filtering and stable pages for browsing without JavaScript.

Microsoft reports 1 vulnerability with exploitation detected in the wild this month. This defender-focused view covers 6,845 vulnerabilities across 17,509 returned patch records from 5 vendors. Filter the complete month, or browse the static page trail without JavaScript.

17,509all patch recordsClear filters2,377criticalShow these records1Microsoft exploitation detectedShow these records3Microsoft in the Known Exploited Vulnerabilities catalogShow these records14,331tracked hereShow these records
Patch records
Returned Microsoft and cross-vendor release records. One Common Vulnerabilities and Exposures (CVE) identifier can appear in more than one record.
Tracked here
Records joined to a vulnerability record in this tracker.
Defender priority
Sorts Microsoft exploitation status, Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog status, severity, and tracker coverage first.
More likely
Microsoft's Exploitability Index rating that exploitation is more likely. It is not a claim that exploitation was detected.

Narrow the complete month

Filters use every patch record in this month, including records on later static pages.

Clear all

My Stack only keeps records whose vendor you have pinned. Pins are the vendors you added to My Stack on the home page. Your pin list is saved only in this browser. Shared view and feed requests include the selected vendor names in their URLs. Pins never change what the tracker collects or scores.

Microsoft-only signal filters exclude records without Microsoft signal data as unknown, report them separately, and never count them as absent. “Tracked here” covers both Microsoft and cross-vendor records.

Loading the complete-month filter index…

An Exploit Prediction Scoring System (EPSS) percentage is the global 30-day exploitation probability in the wild, not specific to you. Do not read it as a complete risk score or as evidence about your environment or impact.

Page 85 of 88 · records 16,801 to 17,000 of 17,509

Microsoft Security Response Center

CVEDateProductMSRC severityOut-of-bandEPSSTitle
CVE-2026-68433 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowOut-of-band1%Microsoft rating unavailablelibceph: bound get_version reply decode to front len
CVE-2026-68446 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailabledrm/vmwgfx: Validate vmw_surface_metadata::array_size
CVE-2026-68229 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Low0%Microsoft rating unavailablemedia: cedrus: skip invalid H.264 reference list entries
CVE-2026-68209 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Low0%Microsoft rating unavailablemedia: sun4i-csi: Return queued buffers on start_streaming() failure
CVE-2026-68117 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Low1%Microsoft rating unavailabletipc: clear sock->sk on the failed-insert path in tipc_sk_create()
CVE-2026-68376 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Low0%Microsoft rating unavailablesctp: fix auth_hmacs array size in struct sctp_cookie
CVE-2026-68107 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0Low0%Microsoft rating unavailabledrm/amdgpu/vcn4: avoid rereading IB param length
CVE-2026-68417 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Low0%Microsoft rating unavailableRDMA/siw: publish QP after initialization
CVE-2026-68302 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0Low1%Microsoft rating unavailableamt: re-read skb header pointers after every pull
CVE-2026-64532 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailable
CVE-2025-46686 ↗cbl2 redis 6.2.18-3LowOut-of-band0%Microsoft rating unavailableRedis through 8.0.3 allows memory consumption via a multi-bulk command composed of many bulks, sent by an authenticated user. This occurs because the server allocates memory for the command arguments of every bulk, even when the command is skipped because of insufficient permissions. NOTE: this is disputed by the Supplier because abuse of the commands network protocol is not a violation of the Redis Security Model.
CVE-2026-64546 ↗azl3 kernel 6.6.144.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailabledrm/edid: fix OOB read in drm_parse_tiled_block()
CVE-2026-45893 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowOut-of-band0%Microsoft rating unavailableapparmor: Fix & Optimize table creation from possibly unaligned memory
CVE-2026-40556 ↗cbl2 nano 6.0-3LowOut-of-bandNot availableMicrosoft rating unavailableInsecure Directory Permissions in GNU nano Leading to Privilege Abuse
CVE-2025-11840 ↗cbl2 binutils 2.37-19LowOut-of-band0%Microsoft rating unavailableGNU Binutils ldmisc.c vfinfo out-of-bounds
CVE-2025-2913 ↗cbl2 hdf5 1.14.4-1LowOut-of-band0%Microsoft rating unavailableHDF5 H5FL.c H5FL__blk_gc_list use after free
CVE-2026-72324 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablegpio: mvebu: free generic chips on unbind
CVE-2026-72321 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer()
CVE-2026-72501 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableRDMA/bnxt_re: Initialize dpi variable to zero
CVE-2026-74559 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablexsk: drain continuation descs after overflow in xsk_build_skb()
CVE-2026-72439 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablemd/raid10: fix writes_pending leak on write request failures
CVE-2026-74487 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablebinfmt_misc: restore write access when removing an entry
CVE-2026-74373 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablemd/raid1,raid10: fix bio accounting for split md cloned bios
CVE-2026-74560 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablexsk: fix buffer leak in xsk_drop_skb() for AF_XDP multi-buffer Tx
CVE-2026-74558 ↗azl3 kernel 6.6.152.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablexsk: reclaim invalid Tx descriptors in ZC batch path
CVE-2026-74543 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablenet: udp_tunnel: fix memory leak in udp_tunnel_nic_unregister()
CVE-2026-74448 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailabledrm/amdkfd: fix QID bit leak in pqm_create_queue()
CVE-2026-74532 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableBluetooth: btintel: Validate length before parsing diagnostics TLV
CVE-2026-82631 ↗azl3 valkey 8.0.10-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablevalkey-io valkey Blocked-on-keys blocked.c handleClientsBlockedOnKey use after free
CVE-2026-82327 ↗azl3 libsolv 0.7.28-5 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableLibsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directory id from vertical/paged .solv filelist data
CVE-2026-15310 ↗azl3 python3 3.12.14-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablezipfile: bzip2/LZMA/Zstandard members decompress without a max_length bound, defeating chunked-read memory limits
CVE-2026-72924 ↗azl3 gh 2.62.0-20 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableGitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default
CVE-2026-80623 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablecoresight: ete: Always save state on power down
CVE-2026-74754 ↗azl3 kernel 6.6.157.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablescsi: core: pair EH runtime PM get and put
CVE-2026-80539 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailabledrm/amdgpu: disallow multiple FENCE chunks in one submit
CVE-2026-80581 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout
CVE-2026-80566 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableInput: hynitron_cstxxx - validate touch count and finger IDs
CVE-2026-74659 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablenet: bridge: mrp: fix uninitialised bytes on the wire
CVE-2026-74658 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablefutex: Prevent robust futex exit race some more
CVE-2026-74676 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablevt: add permission check for KDSKBMETA ioctl
CVE-2026-74671 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableima: fix out-of-bounds read in xattr_verify()
CVE-2026-74679 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableusb: gadget: f_ncm: Use unsigned int for ndp_index
CVE-2026-74719 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablenet/smc: fix qentry overwrite for CONFIRM_LINK and ADD_LINK_CONT in smc_llc_event_handler()
CVE-2026-74673 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableInput: evdev - fix information leak in evdev_pass_values()
CVE-2026-74680 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableusb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm()
CVE-2026-74464 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablenet: openvswitch: fix skb leak on flow key update failure during ct
CVE-2026-73071 ↗azl3 vim 9.2.0782-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableVim: Use-after-free in JSON Decoding
CVE-2026-74577 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablenet: mpls: initialize rtm_tos in mpls_getroute()
CVE-2026-73283 ↗azl3 openssh 9.8p1-9 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableIn sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.
CVE-2026-74525 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablenet: sxgbe: free TX rings on RX allocation failure
CVE-2026-61712 ↗azl3 moby-engine 25.0.3-19 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableBuildKit: Possible runtime DoS via unbounded group parsing
CVE-2026-60589 ↗azl3 python-tensorboard 2.16.2-6 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u501, 11.0.32, 17.0.20, 21.0.12, 25.0.4, 26.0.2; Oracle GraalVM for JDK: 17.0.20 and 21.0.12; Oracle GraalVM Enterprise Edition: 21.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vect
CVE-2026-14666 ↗azl3 postgresql 16.14-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablePostgreSQL row security caching disregards role modifications
CVE-2026-6469 ↗azl3 postgresql 16.14-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablePostgreSQL ALTER TABLE ALTER TYPE resets extended statistics ownership
CVE-2026-14673 ↗azl3 postgresql 16.14-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablePostgreSQL amcheck does not clear untrusted search path
CVE-2026-19411 ↗azl3 shim-unsigned-aarch64 16.1-2 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableShim/dp.c library: null-pointer dereference in is_removable_media_path() when devicepathtostr() returns null
CVE-2026-18503 ↗azl3 python3 3.12.9-14 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableSuper-linear CPU usage for unbounded input to csv.Sniffer.sniff()
CVE-2026-68429 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailabledrm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()
CVE-2026-68450 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablebtrfs: free mapping node on duplicate reloc root insert
CVE-2026-73281 ↗azl3 openssh 9.8p1-9 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableIn ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.
CVE-2026-72712 ↗azl3 nmap 7.95-4 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailableNmap 7.99 Denial of Service via Zero-Length TCP Option Packet
CVE-2026-6368 ↗azl3 glibc 2.38-20 on Azure Linux 3.0LowOut-of-bandNot availableMicrosoft rating unavailablewordexp with WRDE_APPEND can return or use invalid memory
CVE-2026-68304 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablewifi: brcmfmac: fix 802.1X-SHA256 call trace warning
CVE-2026-68269 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailabledrm/i915/gem: Add missing nospec on parallel submit slot
CVE-2026-68301 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablenet: hsr: fix memory leak on slave unregistration by removing synced VLANs
CVE-2026-68248 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailabledrm/i915: Return NULL on error in active_instance
CVE-2026-68309 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablewifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bss_he_tlv()
CVE-2026-68226 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablemedia: cx23885: add ioremap return check and cleanup
CVE-2026-68279 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailabledrm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers
CVE-2026-68422 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablebtrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots()
CVE-2026-68280 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailabledrm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
CVE-2026-68413 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablewifi: ipw2100: fix potential memory leak in ipw2100_pci_init_one()
CVE-2026-68277 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailabledrm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers
CVE-2026-68220 ↗azl3 kernel 6.6.143.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailablemedia: nxp: imx8-isi: Add missing v4l2_subdev_cleanup() in crossbar and pipe
CVE-2026-68234 ↗azl3 kernel 6.6.150.1-1 on Azure Linux 3.0LowNot availableMicrosoft rating unavailabledrm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved

Cross-vendor patches

VendorCVESeverityProductFixed versionPatchAdvisory
SuseCVE-2026-52981trackedCVSS 3.7SUSE Linux Micro 6.0kernel-devel-rt-0:6.4.0-51.1.noarchno patch linkAdvisory ↗
SuseCVE-2026-52981trackedCVSS 3.7SUSE Linux Micro 6.0kernel-default-0:6.4.0-51.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-53045trackedCVSS 2.9SUSE Linux Micro 6.1kernel-devel-rt-0:6.4.0-51.1.noarchno patch linkAdvisory ↗
SuseCVE-2026-53045trackedCVSS 2.9SUSE Linux Micro 6.1kernel-default-0:6.4.0-51.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-53045trackedCVSS 2.9SUSE Linux Micro 6.0kernel-devel-rt-0:6.4.0-51.1.noarchno patch linkAdvisory ↗
SuseCVE-2026-53045trackedCVSS 2.9SUSE Linux Micro 6.0kernel-default-0:6.4.0-51.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-63869trackedCVSS 3.3SUSE Linux Micro 6.1kernel-devel-rt-0:6.4.0-51.1.noarchno patch linkAdvisory ↗
SuseCVE-2026-63869trackedCVSS 3.3SUSE Linux Micro 6.1kernel-default-0:6.4.0-51.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-63869trackedCVSS 3.3SUSE Linux Micro 6.0kernel-devel-rt-0:6.4.0-51.1.noarchno patch linkAdvisory ↗
SuseCVE-2026-63869trackedCVSS 3.3SUSE Linux Micro 6.0kernel-default-0:6.4.0-51.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-64330trackedCVSS 3.5SUSE Linux Micro 6.1kernel-devel-rt-0:6.4.0-51.1.noarchno patch linkAdvisory ↗
SuseCVE-2026-64330trackedCVSS 3.5SUSE Linux Micro 6.1kernel-default-0:6.4.0-51.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-64330trackedCVSS 3.5SUSE Linux Micro 6.0kernel-devel-rt-0:6.4.0-51.1.noarchno patch linkAdvisory ↗
SuseCVE-2026-64330trackedCVSS 3.5SUSE Linux Micro 6.0kernel-default-0:6.4.0-51.1.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-65183trackedCVSS 2.5Red Hat Hardened Imagestomcat11-0:11.0.25-0.1.hum1@noarchPatch ↗Advisory ↗
Red HatCVE-2026-66422trackedCVSS 2.7Red Hat Hardened Imagestomcat11-0:11.0.25-0.1.hum1@noarchPatch ↗Advisory ↗
Red HatCVE-2026-75803trackedCVSS 3.7Red Hat Hardened Imagespython-cryptography-0:50.0.0-1.hum1@srcPatch ↗Advisory ↗
Red HatCVE-2026-16405trackedCVSS 3.4Red Hat Enterprise Linux AppStream AUS (v.8.4)firefox-0:140.13.0-1.el8_4.srcPatch ↗Advisory ↗
Red HatCVE-2026-16405trackedCVSS 3.4Red Hat Enterprise Linux AppStream EUS (v. 10.0)firefox-0:140.13.0-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405trackedCVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.9.4)firefox-0:140.13.0-1.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405trackedCVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.9.2)firefox-0:140.13.0-1.el9_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405trackedCVSS 3.4Red Hat Enterprise Linux Server (v. 7 ELS)firefox-0:140.13.0-1.el7_9.ppc64Patch ↗Advisory ↗
Red HatCVE-2026-16405trackedCVSS 3.4Red Hat Enterprise Linux AppStream EUS (v.9.6)firefox-0:140.13.0-1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405trackedCVSS 3.4Red Hat Enterprise Linux AppStream AUS (v.8.6)firefox-0:140.13.0-1.el8_6.srcPatch ↗Advisory ↗
Red HatCVE-2026-16405trackedCVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.8.8)firefox-0:140.13.0-1.el8_8.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-16405trackedCVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.9.4)thunderbird-0:140.13.0-1.el9_4.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405trackedCVSS 3.4Red Hat Enterprise Linux AppStream EUS (v. 10.0)thunderbird-0:140.13.0-1.el10_0.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405trackedCVSS 3.4Red Hat Enterprise Linux AppStream EUS (v.9.6)thunderbird-0:140.13.0-1.el9_6.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405trackedCVSS 3.4Red Hat Enterprise Linux AppStream AUS (v.8.6)thunderbird-0:140.13.0-1.el8_6.srcPatch ↗Advisory ↗
Red HatCVE-2026-16405trackedCVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.8.8)thunderbird-0:140.13.0-1.el8_8.ppc64lePatch ↗Advisory ↗
Red HatCVE-2026-16405trackedCVSS 3.4Red Hat Enterprise Linux AppStream AUS (v.8.4)thunderbird-0:140.13.0-1.el8_4.srcPatch ↗Advisory ↗
Red HatCVE-2026-16405trackedCVSS 3.4Red Hat Enterprise Linux AppStream E4S (v.9.2)thunderbird-0:140.13.0-1.el9_2.aarch64Patch ↗Advisory ↗
SuseCVE-2026-53045trackedCVSS 2.9SUSE Linux Micro Extras 6.2kernel-obs-build-0:6.12.0-160000.37.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-53045trackedCVSS 2.9SUSE Linux Micro 6.2kernel-64kb-0:6.12.0-160000.37.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-53045trackedCVSS 2.9SUSE Linux Enterprise High Availability Extension 16.0cluster-md-kmp-default-0:6.12.0-160000.37.1.ppc64leno patch linkAdvisory ↗
SuseCVE-2026-64158trackedCVSS 3.3SUSE Linux Micro Extras 6.2kernel-obs-build-0:6.12.0-160000.37.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-64158trackedCVSS 3.3SUSE Linux Micro 6.2kernel-64kb-0:6.12.0-160000.37.1.aarch64no patch linkAdvisory ↗
SuseCVE-2026-64158trackedCVSS 3.3SUSE Linux Enterprise High Availability Extension 16.0cluster-md-kmp-default-0:6.12.0-160000.37.1.ppc64leno patch linkAdvisory ↗
SuseCVE-2026-64413trackedCVSS 2.5openSUSE Tumbleweedkernel-devel-0:7.1.7-1.1.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-53434trackedCVSS 3.7Red Hat JBoss Web Server 7.0 on RHEL 10jws7-tomcat-0:11.0.21-6.redhat_00005.1.el10jws.noarchPatch ↗Advisory ↗
Red HatCVE-2026-53434trackedCVSS 3.7Red Hat JBoss Web Server 7.0.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-55276trackedCVSS 2.3Red Hat JBoss Web Server 7.0 on RHEL 10jws7-tomcat-0:11.0.21-6.redhat_00005.1.el10jws.noarchPatch ↗Advisory ↗
Red HatCVE-2026-55276trackedCVSS 2.3Red Hat JBoss Web Server 7.0.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-59083trackedCVSS 3.7Red Hat JBoss Web Server 7.0 on RHEL 10jws7-tomcat-0:11.0.21-6.redhat_00005.1.el10jws.noarchPatch ↗Advisory ↗
Red HatCVE-2026-59083trackedCVSS 3.7Red Hat JBoss Web Server 7.0.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-16405trackedCVSS 3.4Red Hat Enterprise Linux AppStream (v. 9)thunderbird-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405trackedCVSS 3.4Red Hat Enterprise Linux AppStream (v. 8)thunderbird-0:140.13.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405trackedCVSS 3.4Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.13.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-16405trackedCVSS 3.4Red Hat Enterprise Linux AppStream (v. 10)thunderbird-0:140.13.0-1.el10_2.aarch64Patch ↗Advisory ↗
SuseCVE-2026-62430trackedCVSS 2.9SUSE Linux Enterprise High Performance Computing 12 SP5xen-0:4.12.4_72-3.148.4.x86_64no patch linkAdvisory ↗
SuseCVE-2026-62430trackedCVSS 2.9Open Enterprise Server 23.4xen-0:4.16.7_12-150400.4.89.3.x86_64no patch linkAdvisory ↗
SuseCVE-2026-62430trackedCVSS 2.9openSUSE Tumbleweedxen-0:4.22.0_02-1.1.aarch64no patch linkAdvisory ↗
Red HatCVE-2026-41992CVSS 3.6Red Hat Enterprise Linux BaseOS (v. 9)gzip-0:1.12-2.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-41992CVSS 3.6Red Hat Enterprise Linux BaseOS (v. 10)gzip-0:1.13-4.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-41992CVSS 3.6Red Hat Discovery 2registry.redhat.io/discovery/discovery-server-rhel9@sha256:5efae8059c9c15454abac947b8482412686d60aaf5c104557d463e8282e340af_amd64Patch ↗Advisory ↗
Red HatCVE-2026-82562CVSS 3.7Red Hat Hardened Imagesgrafana12.4-0:12.4.9-0.4.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Temurin Build of OpenJDK 25.0.4.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-45446CVSS 3.7Red Hat Hardened Imagesopenssl3-0:3.5.8-0.1.hum1@srcPatch ↗Advisory ↗
Red HatCVE-2026-45446CVSS 3.7Red Hat Hardened Imagesopenssl-0:3.5.8-0.1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-53584CVSS 3.5Red Hat Hardened Imageslibgit2-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2025-6170CVSS 2.5Red Hat Update Infrastructure 5registry.redhat.io/rhui5/cds-kubernetes-tp-rhel9@sha256:6b19042f120e63358cf2cebd8c53af9e75a5a34a7cfde642c3a88a5ddadf94a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-2297CVSS 3.3Red Hat Update Infrastructure 5registry.redhat.io/rhui5/installer-tp-rhel9@sha256:9a9560142c4c4023279a47bdb144a7f4c2f3e7c96fcac281c29f93b4b21ef235_amd64Patch ↗Advisory ↗
Red HatCVE-2026-35386CVSS 3.6Red Hat Update Infrastructure 5registry.redhat.io/rhui5/installer-tp-rhel9@sha256:9a9560142c4c4023279a47bdb144a7f4c2f3e7c96fcac281c29f93b4b21ef235_amd64Patch ↗Advisory ↗
Red HatCVE-2026-35387CVSS 3.1Red Hat Update Infrastructure 5registry.redhat.io/rhui5/installer-tp-rhel9@sha256:9a9560142c4c4023279a47bdb144a7f4c2f3e7c96fcac281c29f93b4b21ef235_amd64Patch ↗Advisory ↗
Red HatCVE-2026-35388CVSS 2.2Red Hat Update Infrastructure 5registry.redhat.io/rhui5/installer-tp-rhel9@sha256:9a9560142c4c4023279a47bdb144a7f4c2f3e7c96fcac281c29f93b4b21ef235_amd64Patch ↗Advisory ↗
Red HatCVE-2026-3832CVSS 3.7Red Hat Update Infrastructure 5registry.redhat.io/rhui5/cds-kubernetes-tp-rhel9@sha256:6b19042f120e63358cf2cebd8c53af9e75a5a34a7cfde642c3a88a5ddadf94a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-45446CVSS 3.7Red Hat Update Infrastructure 5registry.redhat.io/rhui5/cds-kubernetes-tp-rhel9@sha256:6b19042f120e63358cf2cebd8c53af9e75a5a34a7cfde642c3a88a5ddadf94a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-5419CVSS 3.7Red Hat Update Infrastructure 5registry.redhat.io/rhui5/cds-kubernetes-tp-rhel9@sha256:6b19042f120e63358cf2cebd8c53af9e75a5a34a7cfde642c3a88a5ddadf94a0_amd64Patch ↗Advisory ↗
Red HatCVE-2026-55654CVSS 3.7Red Hat Update Infrastructure 5registry.redhat.io/rhui5/installer-tp-rhel9@sha256:9a9560142c4c4023279a47bdb144a7f4c2f3e7c96fcac281c29f93b4b21ef235_amd64Patch ↗Advisory ↗
Red HatCVE-2026-74976CVSS 3.4Red Hat Enterprise Linux AppStream (v. 9)firefox-0:140.14.0-1.el9_8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-74976CVSS 3.4Red Hat Enterprise Linux AppStream (v. 8)firefox-0:140.14.0-1.el8_10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-74976CVSS 3.4Red Hat Enterprise Linux AppStream (v. 10)firefox-0:140.14.0-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18503CVSS 2.8Red Hat Hardened Imagespython3-12-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-3479CVSS 3.3Red Hat Hardened Imagespython3-12-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Hardened Imagesjava-21-openjdk-0:21.0.12.1.1-1.0.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-14673CVSS 3.8Red Hat Hardened Imagespostgresql17-0:17.11-1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18503CVSS 2.8Red Hat Hardened Imagespython3-11-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-3479CVSS 3.3Red Hat Hardened Imagespython3-11-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Enterprise Linux AppStream (v. 8)java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7OPENJDK ELS 11.0.32.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7OPENJDK ELS 11.0.32.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Hardened Imagesjava-25-openjdk-0:25.0.4.1.1-1.1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18503CVSS 2.8Red Hat Hardened Imagespython3-10-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18739CVSS 2.5Red Hat Hardened Imagespopt-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18743CVSS 2.5Red Hat Hardened Imagespopt-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60190CVSS 2.2Red Hat Enterprise Linux AppStream (v. 8)mecab-0:0.996-2.module+el8.10.0+23550+bd321b9a.aarch64::mysql:8.4Patch ↗Advisory ↗
Red HatCVE-2026-60190CVSS 2.2Red Hat Enterprise Linux AppStream (v. 9)mecab-0:0.996-3.module+el9.8.0+24348+9b27f387.4.aarch64::mysql:8.4Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Enterprise Linux Server (v. 7 ELS)java-1.8.0-openjdk-1:1.8.0.504.b01-1.1.el7_9.i686Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 8u504Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 8u504Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat OpenJDK 11 ELS for RHEL 7java-11-openjdk-1:11.0.32.1.1-1.el7_9.s390xPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Enterprise Linux AppStream (v. 8)java-17-openjdk-1:17.0.20.1.1-1.1.el8.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 17.0.20.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 17.0.20.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Enterprise Linux AppStream EUS (v. 10.0)java-21-openjdk-1:21.0.12.1.1-1.1.el10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 21.0.12.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 21.0.12.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Enterprise Linux AppStream (v. 10)java-25-openjdk-1:25.0.4.1.1-1.1.el10.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Build of OpenJDK 25.0.4.1Not reportedPatch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Hardened Imagesjava-21-openjdk-portable-0:21.0.12.1.1-0.1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-60589CVSS 3.7Red Hat Hardened Imagesjava-25-openjdk-portable-0:25.0.4.1.1-0.1.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-61081CVSS 2.7Red Hat Enterprise Linux AppStream (v. 8)mecab-0:0.996-2.module+el8.10.0+23550+bd321b9a.aarch64::mysql:8.4Patch ↗Advisory ↗
Red HatCVE-2026-61081CVSS 2.7Red Hat Enterprise Linux AppStream (v. 9)mecab-0:0.996-3.module+el9.8.0+24348+9b27f387.4.aarch64::mysql:8.4Patch ↗Advisory ↗
Red HatCVE-2026-61096CVSS 2.9Red Hat Enterprise Linux AppStream (v. 8)mecab-0:0.996-2.module+el8.10.0+23550+bd321b9a.aarch64::mysql:8.4Patch ↗Advisory ↗
Red HatCVE-2026-61096CVSS 2.9Red Hat Enterprise Linux AppStream (v. 9)mecab-0:0.996-3.module+el9.8.0+24348+9b27f387.4.aarch64::mysql:8.4Patch ↗Advisory ↗
Red HatCVE-2026-11525CVSS 3.7Red Hat Openshift Data Foundation 4.18registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:21b851833c425cd0638fa0d97672b30481fe6196a38817955500f10f3516acaa_arm64Patch ↗Advisory ↗
Red HatCVE-2026-22036CVSS 3.7Red Hat Openshift Data Foundation 4.18registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:21b851833c425cd0638fa0d97672b30481fe6196a38817955500f10f3516acaa_arm64Patch ↗Advisory ↗
Red HatCVE-2026-60190CVSS 2.2Red Hat Enterprise Linux AppStream (v. 10)mysql8.4-0:8.4.11-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-61081CVSS 2.7Red Hat Enterprise Linux AppStream (v. 10)mysql8.4-0:8.4.11-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-61096CVSS 2.9Red Hat Enterprise Linux AppStream (v. 10)mysql8.4-0:8.4.11-1.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6733CVSS 3.7Red Hat Openshift Data Foundation 4.18registry.redhat.io/odf4/cephcsi-rhel9-operator@sha256:21b851833c425cd0638fa0d97672b30481fe6196a38817955500f10f3516acaa_arm64Patch ↗Advisory ↗
Red HatCVE-2026-45446CVSS 3.7Red Hat Hardened Imagespython-cryptography-0:50.0.0-1.hum1@srcPatch ↗Advisory ↗
Red HatCVE-2026-59842CVSS 3.7Red Hat Enterprise Linux AppStream (v. 10)libssh-debuginfo-0:0.12.0-3.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-59846CVSS 3.9Red Hat Enterprise Linux AppStream (v. 10)libssh-debuginfo-0:0.12.0-3.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-59849CVSS 3.1Red Hat Enterprise Linux AppStream (v. 10)libssh-debuginfo-0:0.12.0-3.el10_2.aarch64Patch ↗Advisory ↗
Red HatCVE-2026-14673CVSS 3.8Red Hat Hardened Imagespostgresql18-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18503CVSS 2.8Red Hat Hardened Imagespython3-14-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-18503CVSS 2.8Red Hat Hardened Imagespython3-13-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-33551CVSS 3.5Red Hat OpenStack Platform 16.2openstack-keystone-1:16.0.3-2.20260616134936.9d699a7.el8ost.noarchPatch ↗Advisory ↗
Red HatCVE-2026-66484CVSS 3.3Red Hat Hardened Imagescpio-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6879CVSS 2.2Red Hat Hardened Imagespython3-14-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-6879CVSS 2.2Red Hat Hardened Imagespython3-13-main@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-55654CVSS 3.7Red Hat Update Infrastructure 5registry.redhat.io/rhui5/installer-rhel9@sha256:cc0ad7b03c50a4a04058b17aa815c86b8ff06496b2b57db6dbea650415c7f362_amd64Patch ↗Advisory ↗
Red HatCVE-2026-85008CVSS 3.7Red Hat Hardened Imagesnodejs26-0:26.7.0-1.5.2.hum1@aarch64Patch ↗Advisory ↗
Red HatCVE-2026-85008CVSS 3.7Red Hat Hardened Imagesnodejs24-0:24.18.1-0.2.2.hum1@aarch64Patch ↗Advisory ↗

Glossary