Where
-Infinity
0
Severity
7

Important: nginx security update

First published (updated )
Severity
7

Important: freerdp security update

First published (updated )
Severity
7

Important: qt5-qtbase security update

First published (updated )
Severity
7

Important: qt6-qt5compat security update

First published (updated )
Severity
7

Important: gstreamer1-plugins-bad-free security update

First published (updated )
Severity
7

Important: gstreamer1-plugins-bad-free security update

First published (updated )
Severity
7

Important: kernel security, bug fix, and enhancement update

First published (updated )
Severity
7

Important: rhc security update

First published (updated )
Severity
7

Important: python3.12 security update

First published (updated )
Severity
7

Important: kernel security, bug fix, and enhancement update

First published (updated )
Severity
7

Important: kernel security, bug fix, and enhancement update

First published (updated )
Severity
7

Important: libXfont2 security update

First published (updated )
Severity
7
Use After Free

Important: kernel security, bug fix, and enhancement update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

Important: rest security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

Important: xmlrpc-c security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

Important: xmlrpc-c security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.Security Fix(es): FreeRDP: FreeRDP: Memory disclosure or denial of service via crafted RDP update orders (CVE-2026-67301) FreeRDP: FreeRDP: Denial of Service via crafted smartcard cache requests (CVE-2026-67288) FreeRDP: FreeRDP: Denial of Service via heap out-of-bounds read (CVE-2026-67291) FreeRDP: FreeRDP: Heap-buffer-overflow allows arbitrary code execution via crafted RPC response (CVE-2026-55194) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

1 / 2
Source: Red Hat
First published (updated )
Severity
4
Buffer Overflow

Moderate: libxml2 security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7
Use After Free

Important: kernel security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7
Use After Free

Important: kernel security, bug fix, and enhancement update

1 / 2
Source: Red Hat
First published (updated )
Severity
7
Buffer Overflow, Input Validation, Code Injection

.NET is a fast, lightweight and modular platform for creating cross platform applications that work on Linux, macOS and Windows. It particularly focuses on creating console applications, web applications and micro-services. .NET contains a runtime conforming to .NET Standards a set of framework libraries, an SDK containing compilers and a 'dotnet' application to drive everything.SDK version: 8.0.130Runtime version: 8.0.30Security Fix(es): dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651) dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108) ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170) ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300) ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303) dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304) dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302) dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650) dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528) dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649) dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526) dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646) dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525) dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527) dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648) .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659) dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524) .NET: .NET Core: .NET Security Feature Bypass Vulnerability (CVE-2026-62899) .NET: .NET Information Disclosure Vulnerability (CVE-2026-62900) .NET: .NET Denial of Service Vulnerability (CVE-2026-62901) .NET: .NET Elevation of Privilege Vulnerability (CVE-2026-62909) Bug Fix(es) and Enhancement(s): dotnet8.0: Reduce time to detect hanging builds during .NET RPM builds (c10s) [rhel-10.0.z] (JIRA:RHEL-192323) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

1 / 2
Source: Red Hat
First published (updated )
Severity
7
Buffer Overflow, Input Validation, Code Injection

.NET is a fast, lightweight and modular platform for creating cross platform applications that work on Linux, macOS and Windows. It particularly focuses on creating console applications, web applications and micro-services. .NET contains a runtime conforming to .NET Standards a set of framework libraries, an SDK containing compilers and a 'dotnet' application to drive everything.SDK version: 9.0.120Runtime version: 9.0.19Security Fix(es): dotnet: SocketsHttpHandler Http2Connection - HTTP/2 SETTINGS/PING ACK flood causing OOM (CVE-2026-50651) dotnet: .NET Core: Denial of Service via type confusion (CVE-2026-57108) ASP.NET Core: ASP.NET Core: Denial of Service via uncontrolled resource allocation (CVE-2026-56170) ASP.NET Core: ASP.NET Core: Privilege Escalation via Incorrect Authentication Algorithm (CVE-2026-47300) ASP.NET Core: ASP.NET Core: Privilege Elevation via Authentication Bypass (CVE-2026-47303) dotnet: .NET Security Feature Bypass Vulnerability (CVE-2026-47304) dotnet: .NET: Denial of Service vulnerability due to uncontrolled resource allocation (CVE-2026-47302) dotnet: .NET Framework: Privilege escalation via code injection (CVE-2026-50650) dotnet: .NET: Security feature bypass due to incorrect authorization (CVE-2026-50528) dotnet: .NET: Local code execution via deserialization of untrusted data (CVE-2026-50649) dotnet: .NET: Local tampering via improper link resolution (CVE-2026-50526) dotnet: .NET Framework: Local Code Execution via Protection Mechanism Failure (CVE-2026-50646) dotnet: .NET: Denial of Service due to uncontrolled resource allocation (CVE-2026-50525) dotnet: .NET Framework: Denial of Service via network-based buffer overflow (CVE-2026-50527) dotnet: .NET Framework: Remote Denial of Service due to uncontrolled resource allocation (CVE-2026-50648) .NET: .NET: Network Spoofing Vulnerability (CVE-2026-50659) dotnet: .NET Framework: Denial of Service via improper input validation (CVE-2026-50524) .NET: .NET Core: .NET Security Feature Bypass Vulnerability (CVE-2026-62899) .NET: .NET Information Disclosure Vulnerability (CVE-2026-62900) .NET: .NET Denial of Service Vulnerability (CVE-2026-62901) .NET: .NET Elevation of Privilege Vulnerability (CVE-2026-62909) Bug Fix(es) and Enhancement(s): dotnet9.0: Reduce time to detect hanging builds during .NET RPM builds (c10s) [rhel-10.0.z] (JIRA:RHEL-192324) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

1 / 2
Source: Red Hat
First published (updated )
Severity
7
Buffer Overflow, Integer Overflow

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.Security Fix(es): FreeRDP: FreeRDP: Remote code execution or denial of service via heap-based buffer overflow (CVE-2026-64620) FreeRDP: FreeRDP: Double-free vulnerability via crafted .rdp file leading to potential remote code execution (CVE-2026-64621) FreeRDP: FreeRDP: Arbitrary code execution via malicious RDP files (CVE-2026-64624) FreeRDP: FreeRDP: Denial of Service via crafted WindowIcon async message (CVE-2026-67299) FreeRDP: FreeRDP: HTTP Proxy Request Injection via Redirection (CVE-2026-67289) FreeRDP: FreeRDP: Remote code execution or denial of service via audio input integer overflow (CVE-2026-68580) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

1 / 2
Source: Red Hat
First published (updated )
Severity
7
Integer Overflow

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. The xfreerdp client can connect to RDP servers such as Microsoft Windows machines, xrdp, and VirtualBox.Security Fix(es): FreeRDP: FreeRDP: Arbitrary code execution via malicious RDP files (CVE-2026-64624) FreeRDP: FreeRDP: Denial of Service via crafted WindowIcon async message (CVE-2026-67299) FreeRDP: FreeRDP: HTTP Proxy Request Injection via Redirection (CVE-2026-67289) FreeRDP: FreeRDP: Remote code execution or denial of service via audio input integer overflow (CVE-2026-68580) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

1 / 2
Source: Red Hat
First published (updated )
Severity
7

Important: python3.12 security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

Important: nginx security update

1 / 2
Source: Red Hat
First published (updated )
Severity
4

Moderate: kernel security, bug fix, and enhancement update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

Important: yggdrasil security update

1 / 2
Source: Red Hat
First published (updated )
Severity
7

Important: mysql8.4 security, bug fix, and enhancement update

1 / 2
Source: Red Hat
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203