Recent Advisories

Severity ID Title Vendor Product Date Type
LOW 2.7 CVE-2026-9088

Keycloak: keycloak: information disclosure due to user profile permission bypass_CVE-2026-9088

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permi...

Red Hat Red Hat Build of Keycloak CVE
CRITICAL 10 CVE-2026-48907

Joomla Extension – joomlacontenteditor.net – Remote Code Execution in JCE extension for Joomla < 2.9.99.5_CVE-2026-48907

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting i...

joomlacontenteditor.net Joomla Content Editor (JCE) extension for Joomla 1.0.0-2.9.99.4 CVE
HIGH 7.8 CVE-2026-45956

drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl()_CVE-2026-45956

In the Linux kernel, the following vulnerability has been resolved: drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl()...

Linux Linux cf67cc9a29ac19c98bc4fa0e6d14b0c1f592d322 CVE
HIGH 7.1 CVE-2026-45955

md/md-llbitmap: fix percpu_ref not resurrected on suspend timeout_CVE-2026-45955

In the Linux kernel, the following vulnerability has been resolved: md/md-llbitmap: fix percpu_ref not resurrected on suspend timeout When llbitm...

Linux Linux 5ab829f1971dc99f2aac10846c378e67fc875abc CVE
HIGH 7.8 CVE-2026-46242

eventpoll: fix ep_remove struct eventpoll / struct file UAF_CVE-2026-46242

In the Linux kernel, the following vulnerability has been resolved: eventpoll: fix ep_remove struct eventpoll / struct file UAF ep_remove() (via ...

Linux Linux 58c9b016e12855286370dfb704c08498edbc857a CVE
HIGH 8.6 CVE-2026-46273

ibmveth: Disable GSO for packets with small MSS_CVE-2026-46273

In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS Some physical adapters on Pow...

Linux Linux 8641dd85799f85bef5f0d1f87356aaa12cb2195e CVE
HIGH 7.8 CVE-2026-46271

wifi: ath12k: do WoW offloads only on primary link_CVE-2026-46271

In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: do WoW offloads only on primary link In case of multi-link conn...

Linux Linux 32f7b19668bd2894f1a236580c2132fc4b9f4449 CVE
HIGH 8.4 CVE-2026-46270

power: supply: rt9455: Fix use-after-free in power_supply_changed()_CVE-2026-46270

In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix use-after-free in power_supply_changed() Using the...

Linux Linux e86d69dd786e94046b8f5be7df1b9a8226a40b2a CVE
CRITICAL 9.1 CVE-2026-46266

inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP_CVE-2026-46266

In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP Yizhou Zhao repor...

Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 CVE
HIGH 7.5 CVE-2026-46265

RDMA/hns: Fix WQ_MEM_RECLAIM warning_CVE-2026-46265

In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix WQ_MEM_RECLAIM warning When sunrpc is used, if a reset triggere...

Linux Linux ffd541d45726341c1830ff595fd7352b6d1cfbcd CVE