Patch Advisories

Microsoft's monthly release and every non-Microsoft advisory, in one browser. Switch scope below; everything under it follows.

Linux Distribution Advisories

Recent Critical/Important Red Hat CVEs, Ubuntu Security Notices, and Debian Security Advisories in one table. Each source publishes its own advisory format and only Red Hat's carries a per-record severity and CVSS — so priority here is FIRST EPSS, where a listed CVE has current coverage, rather than a cross-source score this app would have to invent. Red Hat: last 30 days, Critical/Important. Ubuntu and Debian: the most recent 20–30 published advisories, each vendor's own feed limit.

  • 684Red Hat CVEs
  • 20Ubuntu Notices
  • 30Debian Advisories
Source

734 of 734 advisories match the current filters, highest FIRST EPSS first.

Linux distribution advisories matching the current filters
Source Advisory Title CVEs Severity EPSS Date
Red Hat CVE-2026-64849 mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) 1 Important 0.164 (96.8th pctl) 2026-08-17
Red Hat CVE-2026-66804 console: console: authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure 1 Important 0.053 (92nd pctl) 2026-08-13
Red Hat CVE-2026-18963 keycloak-services: keycloak-services: Unauthenticated account takeover via reset-credentials flow bypass 1 Critical 0.032 (87.4th pctl) 2026-08-17
Red Hat CVE-2026-66805 console: console: stored DOM XSS via unescaped pod logs in document.write 1 Important 0.015 (73.3rd pctl) 2026-08-10
Red Hat CVE-2026-64564 kernel: sctp: don't free the ASCONF's own transport in DEL-IP processing 1 Important 0.015 (72.2nd pctl) 2026-08-04
Red Hat CVE-2026-71364 awx: project archive extraction allows path traversal file writes 1 Important 0.012 (66.1st pctl) 2026-08-24
Ubuntu USN-8715-1 Linux kernel (Oracle) vulnerabilities 37 Not stated 0.012 (65.2nd pctl) 2026-09-02
Ubuntu USN-8711-1 Libgcrypt vulnerability 1 Not stated 0.011 (63.8th pctl) 2026-09-01
Red Hat CVE-2026-66808 hypershift-addon-operator: hypershift-addon-operator: unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection) 1 Important 0.011 (63.4th pctl) 2026-08-06
Red Hat CVE-2026-62901 .NET: .NET Denial of Service Vulnerability 1 Important 0.011 (62.2nd pctl) 2026-08-11
Red Hat CVE-2026-71471 acm-search-v2-rhel9: search-v2-operator: Hub Search CR Collector.ImageOverride propagated to every spoke as arbitrary container image 1 Important 0.010 (61.1st pctl) 2026-08-12
Ubuntu USN-8661-4 Linux kernel vulnerabilities 21 Not stated 0.010 (59.2nd pctl) 2026-09-02
Ubuntu USN-8703-1 WebKitGTK vulnerabilities 47 Not stated 0.009 (57.6th pctl) 2026-08-31
Red Hat CVE-2026-15307 django: Django: Remote code execution via GeoDjango spatial lookups 1 Important 0.009 (57.1st pctl) 2026-08-04
Red Hat CVE-2026-63639 valkey: Valkey: Remote code execution via use-after-free in stream deserialization 1 Important 0.009 (56.9th pctl) 2026-08-18
Red Hat CVE-2026-5917 libgit2: libgit2: Arbitrary code execution via shell command injection in SSH backend 1 Important 0.009 (56.7th pctl) 2026-08-11
Red Hat CVE-2026-84218 org.jolokia/jolokia-core: Incomplete JNDI Denylist in Jolokia JSR-160 Proxy (Bypass of CVE-2018-1000130 Fix) 1 Important 0.009 (56.7th pctl) 2026-09-01
Red Hat CVE-2026-68763 org.apache.tomcat/tomcat: Apache Tomcat: Denial of Service via HTTP/2 allocation leak 1 Important 0.008 (55.1st pctl) 2026-08-25
Red Hat CVE-2026-76036 chromium-browser: Dawn in Google Chrome: Arbitrary code execution via crafted HTML page 1 Important 0.008 (54.4th pctl) 2026-08-18
Red Hat CVE-2026-48752 incus: Incus has arbitrary file read+write on host via templates/ symlink in malicious image 1 Critical 0.008 (54.4th pctl) 2026-08-21
Red Hat CVE-2026-48749 incus: Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image 1 Critical 0.008 (54.4th pctl) 2026-08-21
Red Hat CVE-2026-71513 nltk: NLTK: Remote Code Execution via AllowlistUnpickler dotted-name bypass 1 Important 0.008 (53.6th pctl) 2026-08-22
Red Hat CVE-2026-48750 incus: Incus has an arbitrary file write on host via `exec-output` symlink in crafted image 1 Critical 0.008 (53.6th pctl) 2026-08-21
Red Hat CVE-2026-65927 tomcat: Apache Tomcat: Access control bypass due to off-by-one error in RewriteValve [N] flag processing 1 Important 0.008 (53.5th pctl) 2026-08-25
Red Hat CVE-2026-66793 governance-policy-addon-controller: governance-policy-addon-controller: arbitrary container image override via ManagedClusterAddOn annotation enables RCE on spoke 1 Important 0.008 (52.6th pctl) 2026-08-18
Download filtered advisories (CSV)

Exactly the 734 advisory(ies) matching the filters above.

Advisory detail

Red Hat CVE-2026-64849 — mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

CVE(s): CVE-2026-64849

Date: 2026-08-17

Severity: Important

FIRST EPSS (highest among the listed CVEs): 0.164 (96.8th pctl)

CVSS v3: 8.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N)

Red Hat CVE-2026-66804 — console: console: authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure

console: console: authenticated SSRF via /ansibletower allows arbitrary host access with full response disclosure

CVE(s): CVE-2026-66804

Date: 2026-08-13

Severity: Important

FIRST EPSS (highest among the listed CVEs): 0.053 (92nd pctl)

CVSS v3: 7.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)

Red Hat CVE-2026-18963 — keycloak-services: keycloak-services: Unauthenticated account takeover via reset-credentials flow bypass

keycloak-services: keycloak-services: Unauthenticated account takeover via reset-credentials flow bypass

CVE(s): CVE-2026-18963

Date: 2026-08-17

Severity: Critical

FIRST EPSS (highest among the listed CVEs): 0.032 (87.4th pctl)

CVSS v3: 9.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)

Red Hat CVE-2026-66805 — console: console: stored DOM XSS via unescaped pod logs in document.write

console: console: stored DOM XSS via unescaped pod logs in document.write

CVE(s): CVE-2026-66805

Date: 2026-08-10

Severity: Important

FIRST EPSS (highest among the listed CVEs): 0.015 (73.3rd pctl)

CVSS v3: 8.0 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)

Red Hat CVE-2026-64564 — kernel: sctp: don't free the ASCONF's own transport in DEL-IP processing

kernel: sctp: don't free the ASCONF's own transport in DEL-IP processing

CVE(s): CVE-2026-64564

Date: 2026-08-04

Severity: Important

FIRST EPSS (highest among the listed CVEs): 0.015 (72.2nd pctl)

CVSS v3: 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Red Hat CVE-2026-71364 — awx: project archive extraction allows path traversal file writes

awx: project archive extraction allows path traversal file writes

CVE(s): CVE-2026-71364

Date: 2026-08-24

Severity: Important

FIRST EPSS (highest among the listed CVEs): 0.012 (66.1st pctl)

CVSS v3: 7.2 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)

Ubuntu USN-8715-1 — Linux kernel (Oracle) vulnerabilities

Several security issues were fixed in the Linux kernel.

CVE(s): CVE-2021-47378, CVE-2025-27558, CVE-2026-23392, CVE-2026-31405, CVE-2026-31414, CVE-2026-31448, CVE-2026-31657, CVE-2026-31668, CVE-2026-43071, CVE-2026-43198, CVE-2026-43493, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331, CVE-2026-52914, CVE-2026-52924, CVE-2026-52931, CVE-2026-52955, CVE-2026-52958, CVE-2026-52982, CVE-2026-52986, CVE-2026-52989, CVE-2026-52993, CVE-2026-52999, CVE-2026-53002, CVE-2026-53006, CVE-2026-53043, CVE-2026-53045, CVE-2026-53088, CVE-2026-53176, CVE-2026-53212, CVE-2026-53224, CVE-2026-53225, CVE-2026-53228, CVE-2026-53246, CVE-2026-53309, CVE-2026-53359

Date: 2026-09-02

FIRST EPSS (highest among the listed CVEs): 0.012 (65.2nd pctl)

Ubuntu USN-8711-1 — Libgcrypt vulnerability

Libgcrypt could be made to expose sensitive information over the network.

CVE(s): CVE-2024-2236

Date: 2026-09-01

FIRST EPSS (highest among the listed CVEs): 0.011 (63.8th pctl)

Red Hat CVE-2026-66808 — hypershift-addon-operator: hypershift-addon-operator: unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection)

hypershift-addon-operator: hypershift-addon-operator: unsanitized hub ConfigMap data passed as CLI arguments to privileged install Job (argument injection)

CVE(s): CVE-2026-66808

Date: 2026-08-06

Severity: Important

FIRST EPSS (highest among the listed CVEs): 0.011 (63.4th pctl)

CVSS v3: 8.7 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N)

Red Hat CVE-2026-62901 — .NET: .NET Denial of Service Vulnerability

.NET: .NET Denial of Service Vulnerability

CVE(s): CVE-2026-62901

Date: 2026-08-11

Severity: Important

FIRST EPSS (highest among the listed CVEs): 0.011 (62.2nd pctl)

CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Red Hat CVE-2026-71471 — acm-search-v2-rhel9: search-v2-operator: Hub Search CR Collector.ImageOverride propagated to every spoke as arbitrary container image

acm-search-v2-rhel9: search-v2-operator: Hub Search CR Collector.ImageOverride propagated to every spoke as arbitrary container image

CVE(s): CVE-2026-71471

Date: 2026-08-12

Severity: Important

FIRST EPSS (highest among the listed CVEs): 0.010 (61.1st pctl)

CVSS v3: 9.0 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L)

Ubuntu USN-8661-4 — Linux kernel vulnerabilities

Several security issues were fixed in the Linux kernel.

CVE(s): CVE-2025-27558, CVE-2026-31414, CVE-2026-31448, CVE-2026-31705, CVE-2026-43198, CVE-2026-43378, CVE-2026-43499, CVE-2026-46266, CVE-2026-46331, CVE-2026-52924, CVE-2026-52989, CVE-2026-53086, CVE-2026-53176, CVE-2026-53212, CVE-2026-53215, CVE-2026-53224, CVE-2026-53225, CVE-2026-53228, CVE-2026-53246, CVE-2026-53359, CVE-2026-64531

Date: 2026-09-02

FIRST EPSS (highest among the listed CVEs): 0.010 (59.2nd pctl)

Ubuntu USN-8703-1 — WebKitGTK vulnerabilities

Several security issues were fixed in WebKitGTK.

CVE(s): CVE-2026-28847, CVE-2026-28883, CVE-2026-28901, CVE-2026-28902, CVE-2026-28903, CVE-2026-28904, CVE-2026-28905, CVE-2026-28907, CVE-2026-28942, CVE-2026-28946, CVE-2026-28947, CVE-2026-28953, CVE-2026-28955, CVE-2026-28958, CVE-2026-28984, CVE-2026-39872, CVE-2026-43658, CVE-2026-43660, CVE-2026-43663, CVE-2026-43676, CVE-2026-43699, CVE-2026-43701, CVE-2026-43705, CVE-2026-43707, CVE-2026-43712, CVE-2026-43713, CVE-2026-43715, CVE-2026-43716, CVE-2026-43720, CVE-2026-43721, CVE-2026-43725, CVE-2026-43726, CVE-2026-43727, CVE-2026-43731, CVE-2026-43732, CVE-2026-43734, CVE-2026-43740, CVE-2026-43742, CVE-2026-43745, CVE-2026-43804, CVE-2026-64713, CVE-2026-64719, CVE-2026-64728, CVE-2026-64730, CVE-2026-64757, CVE-2026-64783, CVE-2026-64787

Date: 2026-08-31

FIRST EPSS (highest among the listed CVEs): 0.009 (57.6th pctl)

Red Hat CVE-2026-15307 — django: Django: Remote code execution via GeoDjango spatial lookups

django: Django: Remote code execution via GeoDjango spatial lookups

CVE(s): CVE-2026-15307

Date: 2026-08-04

Severity: Important

FIRST EPSS (highest among the listed CVEs): 0.009 (57.1st pctl)

CVSS v3: 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Red Hat CVE-2026-63639 — valkey: Valkey: Remote code execution via use-after-free in stream deserialization

valkey: Valkey: Remote code execution via use-after-free in stream deserialization

CVE(s): CVE-2026-63639

Date: 2026-08-18

Severity: Important

FIRST EPSS (highest among the listed CVEs): 0.009 (56.9th pctl)

CVSS v3: 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Red Hat CVE-2026-5917 — libgit2: libgit2: Arbitrary code execution via shell command injection in SSH backend

libgit2: libgit2: Arbitrary code execution via shell command injection in SSH backend

CVE(s): CVE-2026-5917

Date: 2026-08-11

Severity: Important

FIRST EPSS (highest among the listed CVEs): 0.009 (56.7th pctl)

CVSS v3: 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

Red Hat CVE-2026-84218 — org.jolokia/jolokia-core: Incomplete JNDI Denylist in Jolokia JSR-160 Proxy (Bypass of CVE-2018-1000130 Fix)

org.jolokia/jolokia-core: Incomplete JNDI Denylist in Jolokia JSR-160 Proxy (Bypass of CVE-2018-1000130 Fix)

CVE(s): CVE-2026-84218

Date: 2026-09-01

Severity: Important

FIRST EPSS (highest among the listed CVEs): 0.009 (56.7th pctl)

CVSS v3: 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

Red Hat CVE-2026-68763 — org.apache.tomcat/tomcat: Apache Tomcat: Denial of Service via HTTP/2 allocation leak

org.apache.tomcat/tomcat: Apache Tomcat: Denial of Service via HTTP/2 allocation leak

CVE(s): CVE-2026-68763

Date: 2026-08-25

Severity: Important

FIRST EPSS (highest among the listed CVEs): 0.008 (55.1st pctl)

CVSS v3: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)

Red Hat CVE-2026-76036 — chromium-browser: Dawn in Google Chrome: Arbitrary code execution via crafted HTML page

chromium-browser: Dawn in Google Chrome: Arbitrary code execution via crafted HTML page

CVE(s): CVE-2026-76036

Date: 2026-08-18

Severity: Important

FIRST EPSS (highest among the listed CVEs): 0.008 (54.4th pctl)

CVSS v3: 8.3 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)

Red Hat CVE-2026-48752 — incus: Incus has arbitrary file read+write on host via templates/ symlink in malicious image

incus: Incus has arbitrary file read+write on host via templates/ symlink in malicious image

CVE(s): CVE-2026-48752

Date: 2026-08-21

Severity: Critical

FIRST EPSS (highest among the listed CVEs): 0.008 (54.4th pctl)

CVSS v3: 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)

Red Hat CVE-2026-48749 — incus: Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image

incus: Incus has an arbitrary file read+write on host via rootfs/ symlink in malicious image

CVE(s): CVE-2026-48749

Date: 2026-08-21

Severity: Critical

FIRST EPSS (highest among the listed CVEs): 0.008 (54.4th pctl)

CVSS v3: 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)

Red Hat CVE-2026-71513 — nltk: NLTK: Remote Code Execution via AllowlistUnpickler dotted-name bypass

nltk: NLTK: Remote Code Execution via AllowlistUnpickler dotted-name bypass

CVE(s): CVE-2026-71513

Date: 2026-08-22

Severity: Important

FIRST EPSS (highest among the listed CVEs): 0.008 (53.6th pctl)

CVSS v3: 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)

Red Hat CVE-2026-48750 — incus: Incus has an arbitrary file write on host via `exec-output` symlink in crafted image

incus: Incus has an arbitrary file write on host via `exec-output` symlink in crafted image

CVE(s): CVE-2026-48750

Date: 2026-08-21

Severity: Critical

FIRST EPSS (highest among the listed CVEs): 0.008 (53.6th pctl)

CVSS v3: 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)

Red Hat CVE-2026-65927 — tomcat: Apache Tomcat: Access control bypass due to off-by-one error in RewriteValve [N] flag processing

tomcat: Apache Tomcat: Access control bypass due to off-by-one error in RewriteValve [N] flag processing

CVE(s): CVE-2026-65927

Date: 2026-08-25

Severity: Important

FIRST EPSS (highest among the listed CVEs): 0.008 (53.5th pctl)

CVSS v3: 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N)

Red Hat CVE-2026-66793 — governance-policy-addon-controller: governance-policy-addon-controller: arbitrary container image override via ManagedClusterAddOn annotation enables RCE on spoke

governance-policy-addon-controller: governance-policy-addon-controller: arbitrary container image override via ManagedClusterAddOn annotation enables RCE on spoke

CVE(s): CVE-2026-66793

Date: 2026-08-18

Severity: Important

FIRST EPSS (highest among the listed CVEs): 0.008 (52.6th pctl)

CVSS v3: 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.