Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.8 CVE-2026-46260

ipv6: Fix out-of-bound access in fib6_add_rt2node()._CVE-2026-46260

In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bound access in fib6_add_rt2node(). syzbot reported out-of-b...

Linux Linux 50b7c7a255858a85c4636a1e990ca04591153dca CVE
HIGH 7.8 CVE-2026-46259

procfs: fix missing RCU protection when reading real_parent in do_task_stat()_CVE-2026-46259

In the Linux kernel, the following vulnerability has been resolved: procfs: fix missing RCU protection when reading real_parent in do_task_stat() ...

Linux Linux 06fffb1267c9d986687b69d74a46ee332a50575e CVE
HIGH 7.8 CVE-2026-46253

pstore/ram: fix buffer overflow in persistent_ram_save_old()_CVE-2026-46253

In the Linux kernel, the following vulnerability has been resolved: pstore/ram: fix buffer overflow in persistent_ram_save_old() persistent_ram_s...

Linux Linux 201e4aca5aa179e6c69a4dcd36a3562e56b8d670 CVE
HIGH 8.4 CVE-2026-46251

btrfs: fix block_group_tree dirty_list corruption_CVE-2026-46251

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix block_group_tree dirty_list corruption When the incompat flag EXTE...

Linux Linux 14033b08a02916e85ffc5397e4ac15337359f3ae CVE
HIGH 7.3 CVE-2026-46250

MIPS: Work around LLVM bug when gp is used as global register variable_CVE-2026-46250

In the Linux kernel, the following vulnerability has been resolved: MIPS: Work around LLVM bug when gp is used as global register variable On MIP...

Linux Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 CVE
CRITICAL 9.1 CVE-2026-46244

netfilter: nft_inner: Fix IPv6 inner_thoff desync_CVE-2026-46244

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync In nft_inner_parse_l2l3(), ...

Linux Linux 3a07327d10a09379315c844c63f27941f5081e0a CVE
HIGH 8.7 CVE-2026-21837

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API_CVE-2026-21837

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary...

HCLSoftware Digital Experience 9.5 CVE
MEDIUM 6.1 CVE-2026-21826

HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection_CVE-2026-21826

HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host heade...

HCLSoftware Digital Experience & DX Compose 9.5 CVE
MEDIUM 6.1 CVE-2026-21825

HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center_CVE-2026-21825

HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute...

HCLSoftware DX Compose 9.5 CVE
MEDIUM 6.4 CVE-2026-10732

CVE-2026-10732_CVE-2026-10732

All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archive conta...

n/a decompress CVE