Skip to content
Threat Feed

Tag

Product-News

16 briefs RSS
high advisory

Multiple Vulnerabilities in Apache Airflow Providers

Multiple vulnerabilities in Apache Airflow and its providers (FAB, Keycloak, Kafka, Akeyless) could allow unauthenticated or authenticated attackers to perform remote code execution, privilege escalation, or unauthorized data access.

Airflow vulnerability apache-airflow product-news
2t
medium advisory

Grafana Improper Access Control Information Disclosure Vulnerability

An authenticated, remote attacker can exploit a flaw in Grafana to perform unauthorized information disclosure due to improper access control.

Grafana informational product-news directory-traversal vulnerability web-application xss security-advisory denial-of-service
3t 1c updated
high advisory

Multiple Vulnerabilities in Fleet

Fleet is affected by multiple security vulnerabilities that allow unauthenticated or authenticated attackers to perform SQL injection, arbitrary code execution, and unauthorized data manipulation.

Fleet vulnerability web-application product-news
2t
medium advisory

Security Advisory for Grafana MCP Server and mcp-grafana

Grafana Labs has addressed a security vulnerability identified as CVE-2026-19516 affecting the Grafana MCP Server and mcp-grafana components in versions 1.0.0 and earlier.

Grafana MCP Server +1 vulnerability observability product-news
1c
medium advisory

Vivid Media Driver Race Condition Vulnerability

CVE-2026-68204 is a vulnerability in the Linux vivid media driver where a lack of checks for vb2_is_busy() during capability toggling may result in memory instability or race conditions.

vivid informational product-news
1c
medium advisory

NULL Pointer Dereference Vulnerability in MediaTek mt76 Wi-Fi Driver

A NULL pointer dereference vulnerability exists in the MediaTek mt76 driver within the mt76_connac_mcu_uni_bss_he_tlv function, potentially leading to kernel panic or denial-of-service conditions.

mt76 vulnerability denial-of-service kernel firmware informational product-news linux
1c
medium advisory

Integer Overflow in AMD KFD Driver

A 32-bit integer overflow vulnerability in the AMD KFD kernel driver allows for potential memory corruption during CWSR size calculations.

Linux kernel vulnerability linux-kernel amd denial-of-service kernel-vulnerability product-news
1c
medium advisory

Open vSwitch GSO Userspace Truncation Underflow Vulnerability

CVE-2026-68123 is a vulnerability in Open vSwitch related to GSO userspace truncation that may cause an underflow condition during packet processing, potentially impacting memory or system stability.

Open vSwitch vulnerability network-infrastructure product-news
1c
low threat

Kernel Networking Subsystem Vulnerability in dpaa2-eth Driver

CVE-2026-68331 identifies a resource management vulnerability in the dpaa2-eth driver related to improper handling of MAC endpoint devices during disconnection, which may lead to system instability.

exploited dpaa2-eth informational product-news
1c
medium threat

Out-of-Bounds Read in carl9170 Wi-Fi Driver

The carl9170 Wi-Fi driver contains an out-of-bounds read vulnerability due to an off-by-two error in the TX status handler, potentially leading to memory disclosure or system instability.

exploited carl9170 informational product-news
1c
low threat

Memory Reference Leak in Linux Kernel AMD Display Driver

CVE-2026-68256 describes a memory reference leak in the Linux kernel drm/amd/display driver occurring during specific DP alt mode timeout conditions.

exploited drm/amd/display informational product-news vulnerability
1c
medium advisory

Vulnerability in AMD Display Driver for Linux Kernel

A memory management flaw in the AMD display driver (drm/amd/display) for the Linux kernel allows for improper handling of DisplayPort Multi-Stream Transport (DP MST) configurations.

amdgpu vulnerability linux kernel informational product-news linux-kernel kernel-security kernel-vulnerability +1
1t 1c
low advisory

Memory Leak and List Corruption in Intel Stratix 10 Firmware

Intel has patched memory leaks and list corruption vulnerabilities in the stratix10-svc firmware component that could lead to system instability.

Stratix 10 firmware vulnerability informational product-news
medium advisory

Linux Kernel binfmt_misc Privilege Escalation Vulnerability

CVE-2026-68186 describes a vulnerability in the Linux kernel binfmt_misc module where the have_execfd flag is set prematurely, potentially enabling local privilege escalation.

Linux Kernel +1 linux kernel vulnerability privilege-escalation mac802154 cve linux-kernel networking +2
low advisory

Security Updates for HashiCorp Consul

HashiCorp has released security advisory HCSEC-2026-25 addressing multiple vulnerabilities in Consul Community Edition and Consul Enterprise that require immediate patching.

Consul Community Edition +1 informational product-news
1i
high advisory

Linux Kernel MPLS NULL Pointer Dereference Vulnerability

A NULL pointer dereference vulnerability in the Linux kernel's MPLS subsystem, specifically affecting configurations where CONFIG_INET is disabled, can lead to a denial-of-service condition.

Linux Kernel vulnerability linux kernel informational stability cve filesystem product-news +13
2t 1c updated