CVE-2026-104988Pki-core: dogtag-pki: redhat-pki: pki: est fullcmc authentication bypass allows certificate mis-issuance with arbitrary subject Exploitation status Not confirmed Fix Not confirmed Published 10/02/2026 Severity High CVE-2026-95512Freetype: freetype: denial of service via repeated subroutine allocations in cid font loader Exploitation status Not confirmed Fix Not confirmed Published 10/02/2026 Severity Medium CVE-2026-86345389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result Exploitation status Not confirmed Fix Not confirmed Published 10/01/2026 Severity Critical CVE-2026-86344389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue Exploitation status Not known exploited Fix Not confirmed Published 10/01/2026 Severity High CVE-2026-103641Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder Exploitation status Not known exploited Fix Not confirmed Published 10/01/2026 Severity Medium CVE-2026-103399Libsoup: soupserver: http/1 request smuggling via undrained expect: 100-continue body Exploitation status Not known exploited Fix Not confirmed Published 09/30/2026 Severity Medium CVE-2026-103242Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_filesignatures header tag Exploitation status Not known exploited Fix Not confirmed Published 09/30/2026 Severity High CVE-2026-102560Libsoup: libsoup: heap buffer overflow during outgoing permessage-deflate buffer growth Exploitation status Not known exploited Fix Not confirmed Published 09/29/2026 Severity High CVE-2026-102559Libsoup: libsoup: heap buffer overflow during websocket client-frame masking Exploitation status Not known exploited Fix Not confirmed Published 09/29/2026 Severity High CVE-2026-102558Libsoup: libsoup: heap buffer overflow during websocket receive-buffer growth Exploitation status Not known exploited Fix Not confirmed Published 09/29/2026 Severity High CVE-2026-102555Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri base64 decoding Exploitation status Not known exploited Fix Not confirmed Published 09/29/2026 Severity High CVE-2026-102557Libsoup: libsoup: heap buffer overflow during websocket message reassembly Exploitation status Not known exploited Fix Not confirmed Published 09/29/2026 Severity High CVE-2026-102556Libsoup: libsoup: heap buffer overflow from websocket pong signal type confusion Exploitation status Not known exploited Fix Not confirmed Published 09/29/2026 Severity High CVE-2026-95520Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffer overflow when parsing untrusted rpm packages Exploitation status Not known exploited Fix Not confirmed Published 09/29/2026 Severity High CVE-2026-97029Flatpak: flatpak: sandboxed app can signal unsandboxed processes in the same process group Exploitation status Not known exploited Fix Not confirmed Published 09/29/2026 Severity Medium CVE-2026-97024Flatpak: flatpak: arbitrary write in root context via path traversal in deploy directory files/etc Exploitation status Not known exploited Fix Not confirmed Published 09/29/2026 Severity High CVE-2026-97027Flatpak: flatpak: denial of service via unsanitized keys in exported desktop entry / d-bus service files Exploitation status Not known exploited Fix Not confirmed Published 09/28/2026 Severity Low CVE-2026-97026Flatpak: flatpak: world-writable temporary child repositories in system-helper cache path Exploitation status Not known exploited Fix Not confirmed Published 09/28/2026 Severity Low CVE-2026-97025Flatpak: flatpak: world-readable oci authentication token in system-helper cache path Exploitation status Not known exploited Fix Not confirmed Published 09/28/2026 Severity Low CVE-2026-102010Gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: denial of service via use-after-free in binary heap erase_if Exploitation status Not known exploited Fix Not confirmed Published 09/28/2026 Severity High CVE-2026-97023Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy directory export/bin Exploitation status Not known exploited Fix Not confirmed Published 09/28/2026 Severity High CVE-2026-96284Flatpak: flatpak: arbitrary read-access to files in the system-helper context via oci symlink following Exploitation status Not known exploited Fix Not confirmed Published 09/27/2026 Severity Low CVE-2026-96282Flatpak: flatpak: extension metadata path traversal file existence oracle Exploitation status Not known exploited Fix Not confirmed Published 09/27/2026 Severity Low CVE-2026-96283Flatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another user's ongoing pull Exploitation status Not known exploited Fix Not confirmed Published 09/27/2026 Severity Low CVE-2026-96281Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimes Exploitation status Not known exploited Fix Not confirmed Published 09/27/2026 Severity Medium CVE-2026-96280Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems Exploitation status Not known exploited Fix Not confirmed Published 09/27/2026 Severity High CVE-2026-96279Flatpak: flatpak: path traversal issue in oci archive extraction via hardlinks Exploitation status Not known exploited Fix Not confirmed Published 09/27/2026 Severity Medium CVE-2026-93834Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape Exploitation status Public exploit Fix Not confirmed Published 09/25/2026 Severity High CVE-2026-95521Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when installing a source rpm Exploitation status Not known exploited Fix Not confirmed Published 09/24/2026 Severity High CVE-2026-95519Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows) Exploitation status Not known exploited Fix Not confirmed Published 09/24/2026 Severity High CVE-2026-97185Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file Exploitation status Not known exploited Fix Not confirmed Published 09/24/2026 Severity High CVE-2026-96889Librsvg: use-after-free when xml includes have duplicated entities Exploitation status Public exploit Fix Not confirmed Published 09/23/2026 Severity High CVE-2026-96546Gimp: gimp: one-byte out-of-bounds heap read in the uncompressed dds loader Exploitation status Public exploit Fix Not confirmed Published 09/23/2026 Severity Low CVE-2026-96545Gimp: gimp: out-of-bounds heap read in the 4bpp tim image loader Exploitation status Public exploit Fix Not confirmed Published 09/23/2026 Severity Medium CVE-2026-96276Flatpak: flatpak: arbitrary write in host context via flatpak build-init Exploitation status Not known exploited Fix Not confirmed Published 09/23/2026 Severity Critical CVE-2026-96275Flatpak: flatpak: arbitrary write access as root via extra-data extraction Exploitation status Not known exploited Fix Not confirmed Published 09/23/2026 Severity High CVE-2026-96512Sudo: sudo: tz environment variable allows bypass of notbefore/notafter time-based authorization Exploitation status Not known exploited Fix Not confirmed Published 09/23/2026 Severity High CVE-2026-96442Emacs: emacs: arbitrary code execution in flymake mode Exploitation status Not known exploited Fix YesPublished 09/23/2026 Severity High CVE-2026-13087Exploitation status Not confirmed Fix Not confirmed Published 09/22/2026 Severity Unknown CVE-2026-90462Sssd: sssd: fail-open in ldap ppolicy access check allows continued authorization Exploitation status Public exploit Fix Not confirmed Published 09/22/2026 Severity Medium CVE-2026-94640Rpcbind: unbounded memory allocation in rpcbind statistics tracking allows unauthenticated remote denial of service Exploitation status Not known exploited Fix Not confirmed Published 09/22/2026 Severity High CVE-2026-95619Gcc: libstdc++ integer overflow in `new` operator Exploitation status Not known exploited Fix Not confirmed Published 09/22/2026 Severity High CVE-2026-95511Exploitation status Not confirmed Fix Not confirmed Published 09/22/2026 Severity Unknown CVE-2026-93433Libstoragemgmt: libstoragemgmt: denial of service via stack buffer overflow in scsi vpd page parsing Exploitation status Not known exploited Fix Not confirmed Published 09/21/2026 Severity Medium CVE-2026-92382Usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write Exploitation status Not known exploited Fix Not confirmed Published 09/21/2026 Severity Medium CVE-2026-94184Fetchmail: fetchmail: stack-based buffer overflow in ntlm authentication (fetchmail-sa-2026-01) Exploitation status Not known exploited Fix Not confirmed Published 09/21/2026 Severity High CVE-2026-80110Pki-core: dogtag pki v2 rest acl filter's reverse-lexicographic tie-break lets a ca agent invoke the admin-only raw profile creation endpoint Exploitation status Not known exploited Fix Not confirmed Published 09/21/2026 Severity High CVE-2026-91142Cockpit: integer overflow in `do_lastlog()` offset calculation can misaddress `lastlog` entries on ilp32 builds Exploitation status Not known exploited Fix Not confirmed Published 09/18/2026 Severity Low CVE-2026-91147Cockpit: cockpit: denial of service in `cockpit-ws` due to url-root handling without a trailing slash Exploitation status Public exploit Fix Not confirmed Published 09/18/2026 Severity Medium CVE-2026-91149Cockpit: cockpit: denial of service via unbounded connection thread spawning Exploitation status Not known exploited Fix Not confirmed Published 09/18/2026 Severity High CVE-2026-93653Poppler: poppler: unbounded cpu loop in splashoutputdev::tilingpatternfill via unvalidated tiling-pattern repeat count (denial of service) Exploitation status Not known exploited Fix Not confirmed Published 09/18/2026 Severity Medium CVE-2026-81627Qemu-kvm: vapic writable rom alias can escape the option-rom window and expose locked smram Exploitation status Public exploit Fix Not confirmed Published 09/18/2026 Severity High CVE-2026-76781Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attribute Exploitation status Not known exploited Fix Not confirmed Published 09/17/2026 Severity Medium CVE-2026-92091Jwcrypto: jwcrypto: denial of service via o(n^2) duplicate check on unbounded jwk key_ops array Exploitation status Public exploit Fix Not confirmed Published 09/16/2026 Severity Medium CVE-2026-92248Gimp: integer overflow when generating a thumbnail preview for a psd file Exploitation status Not known exploited Fix Not confirmed Published 09/15/2026 Severity High CVE-2026-85234Tftp: tftp-hpa: denial of service due to out-of-bounds read/write in remap engine Exploitation status Not known exploited Fix Not confirmed Published 09/15/2026 Severity High CVE-2026-85013Environment-modules: command injection in environment-modules bash completion via malicious module names containing shell metacharacters Exploitation status Public exploit Fix Not confirmed Published 09/15/2026 Severity High CVE-2026-91786Gnome-shell: gnome-shell: out-of-bounds read in remote search icon rendering due to unvalidated icon-data buffer size Exploitation status Not known exploited Fix Not confirmed Published 09/15/2026 Severity Medium CVE-2026-19816PackageKit: dnf5 backend ignores SIMULATE on RepoRemove Exploitation status Not known exploited Fix YesPublished 09/14/2026 Severity High CVE-2026-90996Sssd: sssd: denial of service in nss responder via crafted zero-length requests Exploitation status Not known exploited Fix Not confirmed Published 09/14/2026 Severity Medium CVE-2026-90995Sssd: sssd: local denial of service due to null pointer dereference in pam responder Exploitation status Not known exploited Fix Not confirmed Published 09/14/2026 Severity Medium CVE-2026-90994Sssd: sssd: denial of service via malformed pam v1 requests Exploitation status Not known exploited Fix Not confirmed Published 09/14/2026 Severity Medium CVE-2026-90463Sssd: local oob read in nss service request parsers (`sss_nss_protocol_parse_svc_name` / `sss_nss_protocol_parse_svc_port`) Exploitation status Not known exploited Fix Not confirmed Published 09/14/2026 Severity Medium CVE-2026-90947Gimp: gimp: out-of-bounds write in lighting effects plugin via crafted preset file Exploitation status Not known exploited Fix Not confirmed Published 09/14/2026 Severity High CVE-2026-90949Gimp: gimp: heap-based buffer overflow in psp loader due to selection-channel geometry mismatch Exploitation status Not known exploited Fix Not confirmed Published 09/14/2026 Severity High CVE-2026-90948Gimp: gimp: heap-based buffer overflow in ico loader via integer overflow in embedded png dimensions Exploitation status Not known exploited Fix Not confirmed Published 09/14/2026 Severity High CVE-2026-89329Device-mapper-multipath: local denial of service via blocking ipc send operations Exploitation status Not known exploited Fix Not confirmed Published 09/11/2026 Severity Medium CVE-2026-18495Libtiff: libtiff: heap-buffer overflow via numeric truncation in the jpeg raw passthrough Exploitation status Not known exploited Fix Not confirmed Published 09/11/2026 Severity Medium CVE-2026-77159Libvirt: unsafe chown in qemutpmemulatorpreparehost() allows arbitrary file ownership change via symlink Exploitation status Public exploit Fix Not confirmed Published 09/11/2026 Severity Medium CVE-2026-88914Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea-608 closed-caption parser Exploitation status Not known exploited Fix Not confirmed Published 09/11/2026 Severity Medium CVE-2026-88924Gvfs: gvfs-admin socket ownership race permits local root Exploitation status Public exploit Fix YesPublished 09/10/2026 Severity High CVE-2026-88859Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restriction Exploitation status Not known exploited Fix Not confirmed Published 09/10/2026 Severity Medium CVE-2026-18147Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrary code execution via crafted url Exploitation status Not known exploited Fix Not confirmed Published 09/09/2026 Severity High CVE-2026-87876Cups: openprinting cups: remaining case-insensitive username matching in scheduler side paths (cve-2026-27447 follow-up) Exploitation status Public exploit Fix Not confirmed Published 09/09/2026 Severity Low CVE-2026-87875Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-length bound Exploitation status Public exploit Fix Not confirmed Published 09/09/2026 Severity Medium CVE-2026-87853Sssd: sssd: idp authentication prefix comparison allows cross-user impersonation Exploitation status Not known exploited Fix Not confirmed Published 09/09/2026 Severity High CVE-2026-18090Gdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted icns rle block Exploitation status Not known exploited Fix Not confirmed Published 09/08/2026 Severity Medium CVE-2026-74860Libxml2: double-free/uaf in libxml2 python bindings Exploitation status Not known exploited Fix Not confirmed Published 09/08/2026 Severity High CVE-2026-76561Pki-core: dogtag/pki: certprofile-import allows code execution via unsanitized profile content (externalprocessconstraint) Exploitation status Not known exploited Fix Not confirmed Published 09/08/2026 Severity High CVE-2026-86469Glib2: toctou symlink race in `g_file_create_replace_destination` fallback path Exploitation status Public exploit Fix Not confirmed Published 09/07/2026 Severity Medium CVE-2026-19843389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editor Exploitation status Not known exploited Fix Not confirmed Published 09/07/2026 Severity High CVE-2026-18922389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property Exploitation status Not known exploited Fix Not confirmed Published 09/07/2026 Severity Critical CVE-2026-18453389-ds-base: 389-ds-base: pre-authentication null pointer dereference via paged results and use_one_backend control in op_shared_search Exploitation status Not known exploited Fix Not confirmed Published 09/07/2026 Severity High CVE-2026-18355389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length lower-bound underflow in sasl_io_start_packet() Exploitation status Not known exploited Fix Not confirmed Published 09/07/2026 Severity High CVE-2026-76560389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule checks via empty bind dn Exploitation status Not known exploited Fix Not confirmed Published 09/07/2026 Severity High CVE-2026-79678Freeipa: idm: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service Exploitation status Not known exploited Fix Not confirmed Published 09/07/2026 Severity High CVE-2026-76578Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci Exploitation status Not known exploited Fix Not confirmed Published 09/07/2026 Severity Critical CVE-2026-76925Flatpak: flatpak: toctou race condition allows symlink redirection Exploitation status Not known exploited Fix Not confirmed Published 09/04/2026 Severity Medium CVE-2026-85534Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during deferred body read Exploitation status Not known exploited Fix Not confirmed Published 09/04/2026 Severity Medium CVE-2026-81666Corosync: corosync: integer overflow in check_memb_commit_token_sanity may bypass message length validation on 32-bit systems Exploitation status Not known exploited Fix Not confirmed Published 09/04/2026 Severity Medium CVE-2026-81665Corosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly Exploitation status Not known exploited Fix Not confirmed Published 09/04/2026 Severity High CVE-2026-85197Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read() via goaway during body upload Exploitation status Public exploit Fix Not confirmed Published 09/04/2026 Severity High CVE-2026-84185Jwcrypto: jwcrypto: general json jws kid binding bypass during jwkset verification Exploitation status Not known exploited Fix Not confirmed Published 09/03/2026 Severity Medium CVE-2026-71224Gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk Exploitation status Not known exploited Fix Not confirmed Published 09/03/2026 Severity Medium CVE-2026-71222Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing Exploitation status Not known exploited Fix Not confirmed Published 09/03/2026 Severity Medium CVE-2026-71221Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemeta Exploitation status Not known exploited Fix Not confirmed Published 09/03/2026 Severity High CVE-2026-71220Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_edit Exploitation status Not known exploited Fix Not confirmed Published 09/03/2026 Severity High CVE-2026-71219Gfs2-utils: gfs2-utils: stack overflow via alloca(1<<di_depth) in hash table traversal Exploitation status Not known exploited Fix Not confirmed Published 09/03/2026 Severity Medium CVE-2026-85150Gstreamer1-plugins-base: gstreamer: null/invalid-pointer dereference in gst_rtsp_message_parse_auth_credentials() when parsing a crafted digest authorization/www-authenticate header Exploitation status Not known exploited Fix Not confirmed Published 09/03/2026 Severity High CVE-2026-84838Rpm: command injection in rpmuncompress via unescaped filenames passed to popen() Exploitation status Not known exploited Fix Not confirmed Published 09/02/2026 Severity High