Vendor advisories
60 alerts in this category.
Vendor-issued security advisories — the official statements from product vendors about vulnerabilities affecting their software, including patch timelines, workarounds, and detection guidance.
Chrome Dev for Android Update
Google Chrome Releases published an advisory on "Chrome Dev for Android Update". Topic areas: google, chrome, browser, patch. Published September 18, 2026. See the original source linked under Referen
GoogleChrome Dev for Desktop Update
Google Chrome Releases published an advisory on "Chrome Dev for Desktop Update". Topic areas: google, chrome, browser, patch. Published September 18, 2026. See the original source linked under Referen
GoogleUSN-8782-1: Rclone vulnerability
It was discovered that Rclone incorrectly handled unauthenticated requests to the remote control API. An attacker could possibly use this issue to execute arbitrary commands as the user invoking rclon
CVE-2026-49980USN-8715-2: Linux kernel (AWS FIPS) vulnerabilities
Siebe Devroe, Héloïse Gollier, and Mathy Vanhoef discovered that the WiFi implementation in the Linux kernel did not properly handle aggregated frames in mesh networks, due to an incorrect fix for CVE
LinuxCVE-2020-24588USN-8714-3: Linux kernel vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - OCFS2 file system;
LinuxCVE-2026-53043USN-8730-3: Linux kernel (Azure) vulnerability
A security issue was discovered in the Linux kernel. An attacker could possibly use this to compromise the system. This update corrects flaws in the following subsystems: - IPv6 networking; - Netfilte
LinuxUSN-8725-2: Linux kernel (AWS) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - NVIDIA Tegra memor
LinuxCVE-2022-50401Extended Stable Update for Desktop
Google Chrome Releases published an advisory on "Extended Stable Update for Desktop". Topic areas: google, chrome, browser, patch. Published September 17, 2026. See the original source linked under Re
GoogleChrome for Android Update
Google Chrome Releases published an advisory on "Chrome for Android Update". Topic areas: google, chrome, browser, patch. Published September 17, 2026. See the original source linked under References
GoogleUSN-8780-1: libsoup vulnerabilities
It was discovered that libsoup incorrectly handled certain URLs when using an HTTP proxy. A remote attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-1467) It was disco
CVE-2026-1467USN-8779-2: Bubblewrap regression
USN-8779-1 fixed vulnerabilities in Bubblewrap. Unfortunately, the fix for CVE-2026-87766 introduced a regression in symlink resolution, preventing certain Flatpak applications from launching. This up
UbuntuCVE-2026-87766USN-8779-1: Bubblewrap vulnerabilities
It was discovered that Bubblewrap incorrectly handled certain temporary directories. A local attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue o
UbuntuCVE-2019-12439USN-8778-1: GStreamer Good Plugins vulnerability
It was discovered that GStreamer Good Plugins did not limit the size of reassembly buffers when processing fragmented RTP packets. A remote attacker could possibly use this issue to cause GStreamer Go
USN-8775-1: SQLite vulnerability
It was discovered that SQLite was vulnerable to a buffer overflow in the sqlar extension. If a user were tricked into opening a specially crafted SQLar archive, an attacker could cause a denial of ser
USN-8771-1: Valkey vulnerabilities
Madelyn Olson discovered that Valkey incorrectly handled TLS connections under certain conditions. A remote attacker could possibly use this issue to cause Valkey to crash, resulting in a denial of se
UbuntuCVE-2026-56684Early Stable Update for Desktop
Google Chrome Releases published an advisory on "Early Stable Update for Desktop". Topic areas: google, chrome, browser, patch. Published September 16, 2026. See the original source linked under Refer
GoogleChrome for Android Update
Google Chrome Releases published an advisory on "Chrome for Android Update". Topic areas: google, chrome, browser, patch. Published September 16, 2026. See the original source linked under References
GoogleUSN-8774-1: libheif vulnerabilities
Ali Firas discovered that libheif incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-62291) Dmitrijs Trizna
CVE-2026-62291Chrome Beta for Desktop Update
Google Chrome Releases published an advisory on "Chrome Beta for Desktop Update". Topic areas: google, chrome, browser, patch. Published September 16, 2026. See the original source linked under Refere
GoogleChrome Beta for Android Update
Google Chrome Releases published an advisory on "Chrome Beta for Android Update". Topic areas: google, chrome, browser, patch. Published September 16, 2026. See the original source linked under Refere
GoogleChrome Beta for iOS Update
Google Chrome Releases published an advisory on "Chrome Beta for iOS Update". Topic areas: google, chrome, browser, patch. Published September 16, 2026. See the original source linked under References
GoogleUSN-8736-2: Perl vulnerabilities
USN-8736-1 fixed vulnerabilities in Perl. This update provides the corresponding fix for Perl on Ubuntu 24.04 LTS. Original advisory details: It was discovered that Perl incorrectly handled certain la
UbuntuCVE-2026-15534DSA-6496-2 nginx - regression update
https://security-tracker.debian.org/tracker/DSA-6496-2
DebianUSN-8773-1: GNU Guix vulnerability
It was discovered that GNU Guix incorrectly made build outputs accessible to local users before their file metadata was finalized. A local attacker could possibly use this issue to gain elevated privi
USN-8772-1: AOM vulnerabilities
It was discovered that AOM incorrectly handled the first-pass statistics buffer in Look-Ahead Processing (LAP) mode. An attacker could possibly use this issue to cause a heap buffer overflow, leading
CVE-2026-56208Extended Stable Update for Desktop
Google Chrome Releases published an advisory on "Extended Stable Update for Desktop". Topic areas: google, chrome, browser, patch. Published September 15, 2026. See the original source linked under Re
GoogleChrome for Android Update
Google Chrome Releases published an advisory on "Chrome for Android Update". Topic areas: google, chrome, browser, patch. Published September 16, 2026. See the original source linked under References
GoogleChrome Stable for iOS Update
Google Chrome Releases published an advisory on "Chrome Stable for iOS Update". Topic areas: google, chrome, browser, patch. Published September 15, 2026. See the original source linked under Referenc
GoogleUSN-8769-1: phpseclib vulnerability
It was discovered that phpseclib did not perform padding validation in constant time when using AES in CBC mode. A remote attacker could possibly use this issue to conduct a padding oracle timing atta
OracleUSN-8767-1: Snapcast vulnerability
It was discovered that Snapcast incorrectly handled crafted JSON-RPC requests. A remote attacker could possibly use this issue to execute arbitrary code or obtain sensitive information.
USN-8766-1: Suricata-Update vulnerability
Guillem Lefait discovered that Suricata-Update did not properly validate destination paths when extracting files referenced by downloaded rule archives. An attacker could possibly use this issue to wr
USN-8768-1: Shibboleth vulnerability
Florian Stuhlmann discovered that Shibboleth incorrectly escaped input when using the ODBC storage plugin. A remote attacker could possibly use this issue to perform SQL injection attacks and obtain s
USN-8765-1: python-sql vulnerability
Cédric Krier discovered that python-sql incorrectly escaped values passed to unary operators. An attacker could possibly use this issue to perform SQL injection attacks.
USN-8770-1: SimpleSAMLphp vulnerabilities
It was discovered that SimpleSAMLphp incorrectly validated cryptographic signatures in XML messages. An authenticated attacker could possibly use this issue to impersonate users or gain elevated privi
UbuntuCVE-2019-3465USN-8764-1: SRT vulnerabilities
It was discovered that SRT did not authenticate certain encryption control messages. A remote attacker could possibly use this issue to downgrade an encrypted connection and inject arbitrary content o
CVE-2026-55868USN-8763-1: kitty vulnerabilities
It was discovered that kitty incorrectly escaped error messages when handling specially crafted terminal escape sequences. A remote attacker could possibly use this issue to execute arbitrary commands
UbuntuCVE-2026-42850USN-8762-1: polkit vulnerability
It was discovered that polkit incorrectly handled cookie input. A local attacker could possibly use this issue to cause polkit to crash, resulting in a denial of service, or execute arbitrary code.
USN-8730-2: Linux kernel (Azure) vulnerability
A security issue was discovered in the Linux kernel. An attacker could possibly use this to compromise the system. This update corrects flaws in the following subsystems: - IPv6 networking; - Netfilte
LinuxUSN-8739-2: ImageMagick vulnerabilities
USN-8739-1 fixed vulnerabilities in ImageMagick. This update provides the corresponding fixes for Ubuntu 24.04 LTS. Original advisory details: It was discovered that ImageMagick incorrectly handled ce
UbuntuCVE-2026-56366USN-8758-1: dracut vulnerability
It was discovered that dracut did not properly shell-quote messages written by the die() function to the emergency hook directory. An attacker on the adjacent network controlling a rogue DHCP server c
CVE-2026-15816Chrome Dev for Android Update
Google Chrome Releases published an advisory on "Chrome Dev for Android Update". Topic areas: google, chrome, browser, patch. Published September 14, 2026. See the original source linked under Referen
GoogleUSN-8752-1: Konsole vulnerability
It was discovered that Konsole incorrectly handled certain URLs under specific circumstances. A remote attacker could possibly use this issue to execute arbitrary code.
USN-8755-1: libvips vulnerability
It was discovered that libvips incorrectly handled specially crafted TIFF images when saving them as HEIF images. An attacker could possibly use this issue to cause libvips to crash, resulting in a de
USN-8754-1: Freeciv vulnerability
It was discovered that Freeciv incorrectly handled certain network packets, resulting in a stack overflow. A remote attacker could possibly use this issue to cause Freeciv clients or servers to crash,
USN-8753-1: libinput vulnerability
It was discovered that libinput did not properly escape device properties. A local attacker could possibly use this issue to inject arbitrary udev properties and execute arbitrary code as root.
USN-8756-1: Yelp vulnerability
It was discovered that Yelp allowed help documents to execute arbitrary scripts. An attacker could possibly use this issue to trick a user into opening a specially crafted help document and obtain sen
USN-8757-1: cgit vulnerability
It was discovered that cgit incorrectly handled repository paths when HTTP cloning was enabled. A remote attacker could possibly use this issue to access files outside the repository and obtain sensit
USN-8563-5: nginx vulnerability
USN-8563-1 fixed vulnerabilities in nginx. The fix for CVE-2026-42533 was backed out in USN-8563-2 because it could cause a regression. This update includes a better fix for CVE-2026-42533. We apologi
NginxCVE-2026-42533USN-8749-1: CivetWeb vulnerabilities
It was discovered that CivetWeb did not correctly handle parsing certain URIs. A remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only a
UbuntuCVE-2025-55763USN-8751-1: Urwid vulnerabilities
Katriel Moses discovered that Urwid used a weak PRNG. A local attacker could possibly use this issue to cause a denial of service or execute arbitrary code.
USN-8750-1: FFmpeg vulnerabilities
Seung Min Shin discovered that FFmpeg did not correctly handle certain memory operations. If a user or automated system were tricked into opening a specially crafted file, an attacker could cause a de
CVE-2026-12706DSA-6496-1 nginx - security update
https://security-tracker.debian.org/tracker/DSA-6496-1
DebianChromium CVE-2026-76036: Buffer overflow in Dawn
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-76036Chromium CVE-2026-85053: Improper resource exposure in CacheStorage
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-85053Chromium CVE-2026-76017: Use after free in Chromoting
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-76017Chromium CVE-2026-76039: Incorrect reference resolution in Core
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-76039Chromium: CVE-2025-2137 Out of bounds read in V8
Microsoft Security Response Center published an advisory on "Chromium: CVE-2025-2137 Out of bounds read in V8". Topic areas: microsoft, windows, azure, patch. Published September 11, 2026. See the ori
CVE-2025-2137Chromium CVE-2026-85042: Use after free in DevTools
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-85042Chromium CVE-2026-85043: Incomplete cleanup in Network
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-85043CVE-2026-85892 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
MicrosoftCVE-2026-85892
Get alerts that match YOUR environment
This page shows everything in the category. Vulnios narrows it down to alerts that affect your actual asset inventory — only the CVEs you need to act on.
Start a free scan