Výsledky hledání

výrobce: Red Hat× v celém archivu zrušit filtry

25 karet z 26 položek CZ · EN/orig

1

1

1

1

5

CISA Adds Six Known Exploited Vulnerabilities to Catalog

CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability CVE-2021-23758 Ajax.NET Professional Deserialization of Untrusted Data Vulnerability CVE-2022-0995 Linux Kernel Out-of-Bounds Write Vulnerability…

KEV ✓ EPSS 0.84 CVE-2015-3246 CVE-2015-5287 CVE-2019-1068 CVE-2021-23758 CVE-2022-0995 CVE-2026-8452 Red Hat Microsoft Citrix veřejná správa US

· CISA Advisories · CISA Adds Six Known Exploited Vulnerabilities to Catalog

Red Hat Ansible Automation Platform 2

Classification: Severe, Solution: Temporary Fix, Exploit Maturity: Not Defined, CVSSv3.1: 7.7, CVEs: CVE-2026-71366, CVE-2026-71364, Summary: CVE-2026-71366 7.7 Awx: notification backends allow ssrf and credential leakage CVE-2026-71364 7.2 Awx: project archive extraction allows path traversal file writes See also: https://access.redhat.com/security/cve/cve-2026-71364

EPSS 0.01 CVSS 7.7 CVE-2026-71364 CVE-2026-71366 Red Hat FI

· NCSC-FI · Red Hat Ansible Automation Platform 2

Red Hat: Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.9, CVEs: CVE-2026-67567, Summary: A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease custom resources (CRs), to bypass existing security controls. The system's HelmRelease controller processes Helm chart templates using its own elevated ServiceAccount privileges without proper validation. This enables the…

EPSS 0.00 CVSS 9.9 CVE-2026-67567 Red Hat FI

· NCSC-FI · Red Hat: Multicloud-operators-subscription: multicloud-operators-subscription: helmrelease chart applied with controller sa without gvk or namespace restriction

1

SPOJENO PŘES CVE NCSC-2026-0326 [1.00] [M/H] Kwetsbaarheden verholpen in Keycloak

Red Hat heeft meerdere kwetsbaarheden verholpen in Keycloak. De kwetsbaarheid met CVE-2026-18963 kan een ongeauthenticeerde externe aanvaller in staat stellen om elke gebruikersaccount over te nemen door een wachtwoordreset af te dwingen. Door deze kwetsbaarheid valt het e-mailverificatieproces bij wachtwoordreset te omzeilen en wachtwoorden van gebruikers te wijzigen. In Keycloak zijn daarnaast kwetsbaarheden aanwezig in de Fine-Grained Admin Permissions (FGAP) v2, waardoor bepaalde beheerders…

EPSS 0.03 CVSS 9.1 CVE-2026-18963 Red Hat Oracle Jackson NL FI

· NCSC-NL · NCSC-2026-0326 [1.00] [M/H] Kwetsbaarheden verholpen in Keycloak · NCSC-FI · Red Hat Build of Keycloak

2

2

Red Hat Multicluster Engine for Kubernetes

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.3, CVEs: CVE-2026-66794, Summary: A flaw was found in the cluster-proxy-addon component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks.

EPSS 0.00 CVSS 9.3 CVE-2026-66794 Red Hat FI

· NCSC-FI · Red Hat Multicluster Engine for Kubernetes

Red Hat Advanced Cluster Management for Kubernetes 2

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.9, CVEs: CVE-2026-70496, CVE-2026-71470, CVE-2026-76139, Summary: Several vulnerabilities fixed. See also: https://access.redhat.com/security/cve/cve-2026-71470, See also: https://access.redhat.com/security/cve/CVE-2026-76139

EPSS 0.00 CVSS 9.9 CVE-2026-70496 CVE-2026-71470 CVE-2026-76139 Red Hat FI

· NCSC-FI · Red Hat Advanced Cluster Management for Kubernetes 2

3

Red Hat Advanced Cluster Management for Kubernetes 2

Classification: Severe, Solution: Not Defined, Exploit Maturity: Not Defined, CVSSv3.1: 9.9, CVEs: CVE-2026-66780, CVE-2026-66783, CVE-2026-66782, CVE-2026-66781, CVE-2026-75924, CVE-2026-75485, CVE-2026-73834, CVE-2026-66793, CVE-2026-71472, CVE-2026-70495, Summary: Multiple vulnerabilities published in Red Hat Advanced Cluster Management for Kubernetes 2

EPSS 0.01 CVSS 9.9 CVE-2026-66780 CVE-2026-66781 CVE-2026-66782 CVE-2026-66783 CVE-2026-66793 CVE-2026-70495 CVE-2026-71472 CVE-2026-73834 CVE-2026-75485 CVE-2026-75924 Red Hat FI

· NCSC-FI · Red Hat Advanced Cluster Management for Kubernetes 2

1

1

Red Hat security advisory (AV26-803)

Serial Number: AV26-803Date: August 11, 2026 As of August 5, 2026, Red Hat is affected by a vulnerability in the following product: Red Hat Advanced Cluster Management for Kubernetes 2 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CVE-2026-10090 - Red Hat Customer Portal 2483292 – (CVE-2026-10090) CVE-2026-10090 multicluster-operators-subscription: multicluster-operators-subscription: namespace…

EPSS 0.00 CVE-2026-10090 Red Hat CA

· Cyber Centre Kanada · Red Hat security advisory (AV26-803)

1

1

Postřehy z bezpečnosti: armáda botů řízená přes herní fóra Steam

Dnešní vydání našich Postřehů z bezpečnosti přináší informace o tom, jak malware řídil armádu WordPressů přes platformu Steam nebo jak se nechal omámit asistent Google Gemini. Dále si na Root.cz můžete přečíst o balíčcích Red Hatu kradoucí přístupové údaje a o českém projektu Phishguard Sentinel chránící internetové uživatele.

WordPress Red Hat Google Steam CZ

· CSIRT.CZ (CZ.NIC) · Postřehy z bezpečnosti: armáda botů řízená přes herní fóra Steam

2

1

Pwn2Own Berlin 2026: Day Three Results and Master of Pw

Following two days of intense competition, Day Three of Pwn2Own Berlin 2026 brought the curtain down on an incredible event. Security researchers delivered their final exploits, pushing enterprise systems to the limit one last time as the race for Master of Pwn came to a close.Day Three added to an already historic event, bringing the final totals to $1,298,250 awarded for 47 unique 0-day vulnerabilities across three days of competition. DEVCORE claimed the title of Master of Pwn with a…

Red Hat Microsoft OpenAI VMware US

· ZDI Blog · Pwn2Own Berlin 2026: Day Three Results and Master of Pw

1

Pwn2Own Berlin 2026 - Day Two Results

Day Two of Pwn2Own Berlin 2026 and the stakes continue to rise! Security researchers are back on the Pwn2Own stage, pushing enterprise systems to their limits as the competition heats up. More exploits, more surprises, and more standout moments are unfolding, so follow along here for live updates as the race for Master of Pwn intensifies. There were plenty of big targets on the schedule today, including SharePoint, Exchange, and Safari.Following an action-packed Day One where $523,000 was…

Microsoft Apple Red Hat Mozilla US

· ZDI Blog · Pwn2Own Berlin 2026 - Day Two Results