Exact snapshot results

353,537 CVE records

CVE ID descending · no relevance ranking

CVE-2026-41091

Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.

PUBLISHEDCISA KEV
Vendor
Microsoft
Product
Microsoft Malware Protection Engine
Provider severity
HIGH
Conflicts
0

CVE-2026-41090

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

PUBLISHED
Vendor
Microsoft
Product
Microsoft 365 Copilot for iOS
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4109

The Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered) plugin for WordPress is vulnerable to unauthorized access of data due to a improper capability check on the get_item_permissions_check() function in all versions up to, and including, 4.1.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read arbitrary order data including customer PII (name, email, phone) by iterating order IDs.

PUBLISHED
Vendor
arraytics
Product
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)
Provider severity
MEDIUM
Conflicts
0

CVE-2026-41089

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, Windows Server 2012 R2 (Server Core installation), Windows Server 2012, Windows Server 2025, Windows Server 2012 (Server Core installation), Windows Server 2016, Windows Server 2019 (Server Core installation), Windows Server 2016 (Server Core installation), Windows Server 2012 R2, Windows Server 2025 (Server Core installation), Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2019
Provider severity
CRITICAL
Conflicts
1

CVE-2026-41088

Access of resource using incompatible type ('type confusion') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows Server 2022, 23H2 Edition (Server Core installation), Windows Server 2025, Windows 11 Version 25H2, Windows Server 2025 (Server Core installation), Windows 11 Version 24H2, Windows 10 Version 21H2, Windows 11 Version 23H2, Windows 11 version 23H2, Windows 10 Version 22H2, Windows Server 2022, Windows 11 version 26H1
Provider severity
HIGH
Conflicts
1

CVE-2026-41087

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

PUBLISHED
Vendor
Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft, Microsoft
Product
Windows 10 Version 22H2, Windows 10 Version 1607, Windows Server 2022, Windows 11 Version 25H2, Windows Server 2019, Windows Server 2025 (Server Core installation), Windows 10 Version 1809, Windows 11 version 26H1, Windows 10 Version 21H2, Windows 11 Version 24H2, Windows Server 2016 (Server Core installation), Windows Server 2016, Windows Server 2019 (Server Core installation), Windows Server 2025
Provider severity
MEDIUM
Conflicts
1

CVE-2026-41086

Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network.

PUBLISHED
Vendor
Microsoft
Product
Windows Admin Center in Azure Portal
Provider severity
HIGH
Conflicts
0

CVE-2026-41085

Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an authenticated user with limited access privileges to gain unauthorized administrator-level privileges through exploitation of specific system interfaces.

PUBLISHED
Vendor
n/a
Product
n/a
Provider severity
HIGH
Conflicts
1

CVE-2026-41084

A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstances`) evaluated authorization against the `dag_id` resolved from the URL path while operating on the `dag_id` / `dag_run_id` extracted from request-body entity fields. An authenticated UI/API user with edit permission on one Dag could mutate Task Instance state in any other Dag by keeping the authorized Dag's ID in the URL path and naming the target Dag's IDs in the request body

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Airflow
Provider severity
HIGH
Conflicts
0

CVE-2026-41082

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

PUBLISHED
Vendor
Red Hat, OCaml
Product
Red Hat Enterprise Linux 10, opam
Provider severity
HIGH
Conflicts
3

CVE-2026-41081

Improper Handling of TLS Client Authentication Failure Leading to Anonymous Principal Assignment in Apache Storm Versions Affected: up to 2.8.7 Description: When TLS transport is enabled in Apache Storm without requiring client certificate authentication (the default configuration), the TlsTransportPlugin assigns a fallback principal (CN=ANONYMOUS) if no client certificate is presented or if certificate verification fails. The underlying SSLPeerUnverifiedException is caught and suppressed rath

PUBLISHED
Vendor
Apache Software Foundation
Product
Apache Storm Client
Provider severity
MEDIUM
Conflicts
0

CVE-2026-41080

libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.

PUBLISHED
Vendor
Siemens, libexpat project, Siemens, Siemens, Siemens, Siemens
Product
SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, libexpat, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIPLUS S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
Provider severity
HIGH, LOW
Conflicts
2

CVE-2026-4108

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report.

PUBLISHED
Vendor
Zohocorp
Product
ManageEngine Exchange Reporter Plus
Provider severity
HIGH
Conflicts
0

CVE-2026-41079

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP backend that causes an out-of-bounds read of up to 176 bytes past a stack buffer. The leaked memory is converted from UTF-16 to UTF-8 and stored as printer supply description strings, which are subsequently visible to authenticated users via IPP Get-Printer-Attributes responses and the CUPS web interfac

PUBLISHED
Vendor
OpenPrinting
Product
cups
Provider severity
MEDIUM
Conflicts
1

CVE-2026-41078

OpenTelemetry dotnet is a dotnet telemetry framework. In 1.6.0-rc.1 and earlier, OpenTelemetry.Exporter.Jaeger may allow sustained memory pressure when the internal pooled-list sizing grows based on a large observed span/tag set and that enlarged size is reused for subsequent allocations. Under high-cardinality or attacker-influenced telemetry input, this can increase memory consumption and potentially cause denial of service. There is no plan to fix this issue as OpenTelemetry.Exporter.Jaeger w

PUBLISHED
Vendor
open-telemetry, open-telemetry
Product
OpenTelemetry.Exporter.Jaeger, opentelemetry-dotnet
Provider severity
MEDIUM
Conflicts
1

CVE-2026-41076

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.9 and prior in addition to 6.0.0 through 6.0.2 contain an authentication bypass vulnerability in RT installations that use LDAP/AD for user authentication. Under certain LDAP server configurations, an attacker may be able to authenticate as any LDAP-backed RT user without supplying valid credentials. This issue has been fixed in versions 5.0.10 and 6.0.3. If developers are unable to upgrade immediately, they c

PUBLISHED
Vendor
bestpractical
Product
rt
Provider severity
HIGH
Conflicts
0

CVE-2026-41075

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injection vulnerability. An authenticated user can craft input that is incorporated into database queries without proper validation, potentially allowing them to read or modify data in the RT database. This issue has been fixed in versions 5.0.10 and 6.0.3. If developers are unable to upgrade immediately, they can temporarily work around this issue by restr

PUBLISHED
Vendor
bestpractical
Product
rt
Provider severity
HIGH
Conflicts
0

CVE-2026-41074

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in RT user to visit a malicious web page can trigger arbitrary state-changing actions in RT on that user's behalf. This issue has been fixed in version 6.0.3.

PUBLISHED
Vendor
bestpractical
Product
rt
Provider severity
HIGH
Conflicts
0

CVE-2026-41073

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.2 contain a spreadsheet (CSV/formula) injection vulnerability. User-controlled data in spreadsheet exports is not sanitized before being written to the output file, which can cause spreadsheet applications to interpret crafted values as formulas or macros when the file is opened. This issue has been fixed in versions 5.0.10 and 6.0.3. If developers are unable to upgrade immedia

PUBLISHED
Vendor
bestpractical
Product
rt
Provider severity
MEDIUM
Conflicts
0

CVE-2026-41071

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes a heap-buffer-overflow (out-of-bounds read) in the SampleAuxInfoReader constructor. The SampleAuxInfoReader constructor iterates over saiz->get_num_samples() samples but doesn't validate that this count is consistent with the number of chunks in the chunks vector. When saiz declares mo

PUBLISHED
Vendor
strukturag
Product
libheif
Provider severity
MEDIUM
Conflicts
0

CVE-2026-41070

openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version 1.26.3 to before version 1.27.3, when openvpn-auth-oauth2 is deployed in the experimental plugin mode (shared library loaded by OpenVPN via the plugin directive), clients that do not support WebAuth/SSO (e.g., the openvpn CLI on Linux) are incorrectly admitted to the VPN despite being denied by the authentication logic. The default management-interf

PUBLISHED
Vendor
jkroepke
Product
openvpn-auth-oauth2
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4107

Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report.

PUBLISHED
Vendor
Zohocorp
Product
ManageEngine Exchange Reporter Plus
Provider severity
HIGH
Conflicts
0

CVE-2026-41069

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_count == 0 (creating no chunks) while still passing validation because saio.entry_count == 0 matches, but with saiz.sample_count > 0 the SampleAuxInfoReader constructor still enters its loop. This leads to an out-of-bounds dereference on the empty chunks[0] in ch

PUBLISHED
Vendor
strukturag
Product
libheif
Provider severity
MEDIUM
Conflicts
1

CVE-2026-41068

Kyverno is a policy engine designed for cloud native platform engineering teams. The patch for CVE-2026-22039 fixed cross-namespace privilege escalation in Kyverno's `apiCall` context by validating the `URLPath` field. However, the ConfigMap context loader has the identical vulnerability — the `configMap.namespace` field accepts any namespace with zero validation, allowing a namespace admin to read ConfigMaps from any namespace using Kyverno's privileged service account. This is a complete RBAC

PUBLISHED
Vendor
kyverno
Product
kyverno
Provider severity
HIGH
Conflicts
0

CVE-2026-41067

Astro is a web framework. Prior to 6.1.6, the defineScriptVars function in Astro's server-side rendering pipeline uses a case-sensitive regex /<\/script>/g to sanitize values injected into inline <script> tags via the define:vars directive. HTML parsers close <script> elements case-insensitively and also accept whitespace or / before the closing >, allowing an attacker to bypass the sanitization with payloads like </Script>, </script >, or </script/> and inject arbitrary HTML/JavaScript. This vu

PUBLISHED
Vendor
withastro
Product
astro
Provider severity
MEDIUM
Conflicts
0

CVE-2026-41066

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input to read local files. Setting the resolve_entities option explicitly to resolve_entities='internal' or resolve_entities=False disables the local file access. This vulnerability is fixed in 6.1.0.

PUBLISHED
Vendor
lxml
Product
lxml
Provider severity
HIGH
Conflicts
0

CVE-2026-41065

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 are vulnerable to remote code execution via the newsletter custom template directory feature. On a fresh install before the setup wizard is completed, all management endpoints are completely unauthenticated. An attacker can create a newsletter agent, point the custom template directory to an attacker-controlled SMB share serving a malicious Mako template, and trigger execution via the newslett

PUBLISHED
Vendor
Tautulli
Product
Tautulli
Provider severity
HIGH
Conflicts
0

CVE-2026-41064

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` for wget but leaves the `file_get_contents` and `curl` code paths unsanitized, and the URL validation regex `/^http/` accepts strings like `httpevil[.]com`. Commit 78bccae74634ead68aa6528d631c9ec4fd7aa536 contains an updated fix.

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
CRITICAL
Conflicts
0

CVE-2026-41063

WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSafeWithLinks` class overrides `inlineMarkup` for raw HTML but does not override `inlineLink()` or `inlineUrlTag()`, allowing `javascript:` URLs in markdown link syntax to bypass sanitization. Commit cae8f0dadbdd962c89b91d0095c76edb8aadcacf contains an updated fix.

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-41062

WWBN AVideo is an open source video platform. In versions 29.0 and below, the directory traversal fix introduced in commit 2375eb5e0 for `objects/aVideoEncoderReceiveImage.json.php` only checks the URL path component (via `parse_url($url, PHP_URL_PATH)`) for `..` sequences. However, the downstream function `try_get_contents_from_local()` in `objects/functionsFile.php` uses `explode('/videos/', $url)` on the **full URL string** including the query string. An attacker can place the `/videos/../../

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-41061

WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/video.php:918` uses `/^[0-9]{1,2}:[0-9]{1,2}:[0-9]{1,2}/` without a `$` end anchor, allowing arbitrary HTML/JavaScript to be appended after a valid duration prefix. The crafted duration is stored in the database and rendered without HTML escaping via `echo Video::getCleanDuration()` on trending pages, playlist pages, and video gallery thumbnails, resulting in stored cross-site scri

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
MEDIUM
Conflicts
0

CVE-2026-41060

WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/functions.php` contains a same-domain shortcircuit (lines 4290-4296) that allows any URL whose hostname matches `webSiteRootURL` to bypass all SSRF protections. Because the check compares only the hostname and ignores the port, an attacker can reach arbitrary ports on the AVideo server by using the site's public hostname with a non-standard port. The response body is saved to a we

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
HIGH
Conflicts
0

CVE-2026-4106

The HT Mega Addons for Elementor WordPress plugin before 3.0.7 contains an unauthenticated AJAX action returning some PII (such as full name, city, state and country) of customers who placed orders in the last 7 days

PUBLISHED
Vendor
Unknown
Product
HT Mega Addons for Elementor
Provider severity
MEDIUM
Conflicts
1

CVE-2026-41059

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when all of the following are true: Use of `skip_auth_routes` or the legacy `skip_auth_regex`; use of patterns that can be widened by attacker-controlled suffixes, such as `^/foo/.*/bar$` causing potential exposure of `/foo/secret`; and protected upstream applications that interpret `#` as a fragment deli

PUBLISHED
Vendor
oauth2-proxy
Product
oauth2-proxy
Provider severity
HIGH
Conflicts
0

CVE-2026-41058

WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `deleteDump` parameter does not apply path traversal filtering, allowing `unlink()` of arbitrary files via `../../` sequences in the GET parameter. Commit 3c729717c26f160014a5c86b0b6accdbd613e7b2 contains an updated fix.

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
HIGH
Conflicts
0

CVE-2026-41057

WWBN AVideo is an open source video platform. In versions 29.0 and below, the CORS origin validation fix in commit `986e64aad` is incomplete. Two separate code paths still reflect arbitrary `Origin` headers with credentials allowed for all `/api/*` endpoints: (1) `plugin/API/router.php` lines 4-8 unconditionally reflect any origin before application code runs, and (2) `allowOrigin(true)` called by `get.json.php` and `set.json.php` reflects any origin with `Access-Control-Allow-Credentials: true`

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
HIGH
Conflicts
0

CVE-2026-41056

WWBN AVideo is an open source video platform. In versions 29.0 and below, the `allowOrigin($allowAll=true)` function in `objects/functions.php` reflects any arbitrary `Origin` header back in `Access-Control-Allow-Origin` along with `Access-Control-Allow-Credentials: true`. This function is called by both `plugin/API/get.json.php` and `plugin/API/set.json.php` — the primary API endpoints that handle user data retrieval, authentication, livestream credentials, and state-changing operations. Combin

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
HIGH
Conflicts
0

CVE-2026-41055

WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks proxy adds `isSSRFSafeURL()` validation but leaves DNS TOCTOU vulnerabilities where DNS rebinding between validation and the actual HTTP request redirects traffic to internal endpoints. Commit 8d8fc0cadb425835b4861036d589abcea4d78ee8 contains an updated fix.

PUBLISHED
Vendor
WWBN
Product
AVideo
Provider severity
HIGH
Conflicts
0

CVE-2026-41054

In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/entropy/haveged`). However, while it detects if the connecting user is not root (`cred.uid != 0`) and prepares a negative acknowledgement (`ASCII_NAK`), it **fails to stop execution**. The code proceeds to the `switch` statement, allowing any local unprivileged user to execute privileged commands such as `MAGIC_CHROOT`.

PUBLISHED
Vendor
SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE, SUSE
Product
SUSE Linux Enterprise Server 15 SP4-LTSS, SUSE Linux Enterprise Micro 5.5, SUSE Linux Enterprise Server 15 SP5-LTSS, SUSE Linux Enterprise Server 15 SP5-LTSS, SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS, SUSE Linux Enterprise Module for Basesystem 15 SP7, SUSE Linux Enterprise Micro 5.5, SUSE Linux Enterprise Server 15 SP7, Image SLES15-SP4-SAP-BYOS, Image SLES15-SP4-SAP-BYOS, SUSE Linux Enterprise High Performance Computing 15 SP7, SUSE Linux Enterprise Server for SAP Applications 15 SP5, SUSE Manager Retail Branch Server LTS 4.3, SUSE Linux Enterprise Micro 5.3, Container suse/sle-micro-rancher/5.3:latest, Image SLES15-SP4-SAP-Hardened-BYOS-GCE, SUSE Linux Enterprise Server for SAP Applications 15 SP7, SUSE Manager Server LTS 4.3, SUSE Linux Enterprise Server 15 SP4-LTSS, SUSE Manager Retail Branch Server LTS 4.3, Image SLES15-SP4-SAP-Hardened-BYOS, Image SLES15-SP4-SAP-Hardened, Image SLES15-SP4-SAP-Hardened-BYOS-Azure, Container suse/sle-micro/5.5:latest, SUSE Linux Enterprise Server for SAP Applications 15 SP7, SUSE Linux Enterprise Server 15 SP6-LTSS, SUSE Manager Proxy LTS 4.3, SUSE Manager Server LTS 4.3, Image SLES15-SP4-SAP-Hardened-GCE, Image SLES15-SP4-SAP-BYOS-GCE, Image SLES15-SP4-SAP-BYOS-Azure, Image SLES15-SP4-SAP-Hardened-GCE, SUSE Linux Enterprise High Performance Computing 15 SP7, SUSE Linux Enterprise Server for SAP Applications 15 SP4, SUSE Linux Enterprise Server 15 SP6-LTSS, SUSE Linux Enterprise Server for SAP Applications 15 SP6, SUSE Linux Enterprise Desktop 15 SP7, Container suse/sle-micro/5.5:latest, Image SLES15-SP4-SAP-Hardened-BYOS, SUSE Linux Enterprise Module for Basesystem 15 SP7, Container suse/sle-micro-rancher/5.4:latest, SUSE Linux Enterprise Server 15 SP6-LTSS, Container suse/sle-micro-rancher/5.3:latest, SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS, Image SLES15-SP4-SAP-Hardened, SUSE Linux Enterprise Desktop 15 SP7, SUSE Linux Enterprise Server 15 SP7, SUSE Linux Enterprise Server 15 SP4-LTSS, SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS, SUSE Linux Enterprise Server 15 SP5-LTSS, SUSE Linux Enterprise Server for SAP Applications 15 SP7, SUSE Manager Proxy LTS 4.3, SUSE Linux Enterprise Server for SAP Applications 15 SP5, SUSE Linux Enterprise Server for SAP Applications 15 SP6, SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS, Image SLES15-SP4-SAP-BYOS-EC2, SUSE Manager Proxy LTS 4.3, SUSE Linux Enterprise Server 15 SP7, SUSE Manager Retail Branch Server LTS 4.3, SUSE Linux Enterprise Micro 5.3, SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS, Image SLES15-SP4-SAP-BYOS-GCE, SUSE Linux Enterprise Server for SAP Applications 15 SP4, SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS, SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS, SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS, SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS, SUSE Linux Enterprise Desktop 15 SP7, Image SLES15-SP4-SAP-Hardened-BYOS-GCE, SUSE Linux Enterprise Server for SAP Applications 15 SP6, Image SLES15-SP4-SAP-Hardened-BYOS-EC2, SUSE Linux Enterprise High Performance Computing 15 SP7, Image SLES15-SP4-SAP-Hardened-BYOS-EC2, SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS, SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS, Image SLES15-SP4-SAP-Hardened-BYOS-Azure, SUSE Linux Enterprise Micro 5.4, Container suse/sle-micro-rancher/5.4:latest, SUSE Linux Enterprise Micro 5.4, Image SLES15-SP4-SAP-BYOS-EC2, SUSE Linux Enterprise Server for SAP Applications 15 SP4, SUSE Linux Enterprise Module for Basesystem 15 SP7, SUSE Linux Enterprise Server for SAP Applications 15 SP5, Image SLES15-SP4-SAP-BYOS-Azure, SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS, SUSE Manager Server LTS 4.3
Provider severity
HIGH
Conflicts
1

CVE-2026-41053

Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused it granting principal access to any logged in user, in 2.13 before 2.13.6 and 2.14 before 2.14.2.

PUBLISHED
Vendor
SUSE
Product
Rancher
Provider severity
HIGH
Conflicts
0

CVE-2026-41052

Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.

PUBLISHED
Vendor
SUSE
Product
Rancher
Provider severity
CRITICAL
Conflicts
0

CVE-2026-41051

csync2 uses insecure temporary directories when compiled with C99 or later, allowing for TOCTOU style attacks on the temporary directories.

PUBLISHED
Vendor
SUSE
Product
openSUSE Tumbleweed
Provider severity
MEDIUM
Conflicts
1

CVE-2026-41050

Fleet's Helm deployer did not fully apply ServiceAccount impersonation in two code paths, allowing a tenant with git push access to a Fleet-monitored repository to read secrets from any namespace on every downstream cluster targeted by their `GitRepo`.

PUBLISHED
Vendor
SUSE
Product
Rancher
Provider severity
CRITICAL
Conflicts
0

CVE-2026-4105

A flaw was found in systemd. The systemd-machined service contains an Improper Access Control vulnerability due to insufficient validation of the class parameter in the RegisterMachine D-Bus (Desktop Bus) method. A local unprivileged user can exploit this by attempting to register a machine with a specific class value, which may leave behind a usable, attacker-controlled machine object. This allows the attacker to invoke methods on the privileged object, leading to the execution of arbitrary com

PUBLISHED
Vendor
Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Red Hat Enterprise Linux 8, Red Hat OpenShift Container Platform 4, Red Hat OpenShift Container Platform 4, Red Hat Enterprise Linux 10, Red Hat OpenShift Container Platform 4, Red Hat Hardened Images, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Provider severity
MEDIUM
Conflicts
1

CVE-2026-41049

Incorrect caching of authentication between different users of the  qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus functions after a privileged users has authenticated for them.

PUBLISHED
Vendor
presire
Product
qSnapper
Provider severity
HIGH
Conflicts
0

CVE-2026-41048

Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like "restore from snapshot" even if only allowed to do "delete snapshot".

PUBLISHED
Vendor
presire
Product
qSnapper
Provider severity
HIGH
Conflicts
0

CVE-2026-41047

Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacker to see otherwise read protected information.

PUBLISHED
Vendor
presire
Product
qSnapper
Provider severity
MEDIUM
Conflicts
0

CVE-2026-41046

A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or potentially escalate privileges to root.

PUBLISHED
Vendor
presire
Product
qSnapper
Provider severity
HIGH
Conflicts
0

CVE-2026-41045

A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass qSnappers authentication mechanism and operate e.g. as root user.

PUBLISHED
Vendor
presire
Product
qSnapper
Provider severity
HIGH
Conflicts
0

CVE-2026-41044

A flaw was found in Apache ActiveMQ. An authenticated attacker can exploit an improper input validation vulnerability in the admin web console to craft a malicious broker name. This malicious name, containing an xbean binding, can be used by a virtual machine (VM) transport to load a remote Spring XML application. By triggering the VM transport creation, the attacker can execute arbitrary code on the broker's Java Virtual Machine (JVM).

PUBLISHED
Vendor
Apache Software Foundation, Apache Software Foundation, Red Hat, Red Hat, Red Hat, Apache Software Foundation, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat, Red Hat
Product
Apache ActiveMQ Broker, Apache ActiveMQ, Red Hat Data Grid 8, Red Hat Fuse 7, Red Hat Enterprise Linux 8, Apache ActiveMQ All, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Enterprise Linux 9, Red Hat AMQ Broker 7, Red Hat Fuse 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform 7
Provider severity
HIGH
Conflicts
3