Vulnerabilities
Summary — last 7 days
New vulnerabilities3,070▲ 562 vs. last week
Critical / high1,457▲ 278 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)383▲ 176 vs. last week
6,125 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Medium (6.5) | — | — | Redhat Satellite KatelloAI | 10/1/2026 | 10/1/2026 | A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController. The methods check_blob_push_org_label and get_matching_products_from_org take… | |
| Awaiting Analysis | High (7.5) | — | — | Redhat ForemanAIRedhat SatelliteAI | 10/1/2026 | 10/1/2026 | A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a… | |
| Awaiting Analysis | High (7.1) | — | — | Redhat Oc-mirrorAI | 10/1/2026 | 10/1/2026 | A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the local system. An unauthenticated attacker on an adjacent network can connect to the exposed service to push tampered… | |
| Awaiting Analysis | High (7.3) | 0.19% | — | Redhat Oc-mirrorAI | 9/30/2026 | 9/30/2026 | Path traversal / arbitrary file write in oc-mirror's operator catalog image extraction. When mirroring operator catalogs using either the legacy v1 path (--v1) or the OCI feature path (--use-oci-feature), oc-mirror extracts tar entries from catalog image layers without validating that file paths resolve within the… | |
| Awaiting Analysis | Medium (6.8) | 0.45% | — | Redhat Ansible Automation PlatformAI | 9/24/2026 | 9/24/2026 | An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because service-key creation is not restricted to the installer-provisioned provisioning path, an… | |
| Awaiting Analysis | Medium (6.6) | 0.29% | — | Redhat Ansible Automation PlatformAI | 9/23/2026 | 9/26/2026 | An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable without running the integer validation defined elsewhere for that field, and the dispatcher flattens the management-command… | |
| Awaiting Analysis | Medium (6.6) | 0.18% | — | Redhat Automation ControllerAI | 9/23/2026 | 9/24/2026 | — | |
| Awaiting Analysis | High (7.1) | 0.29% | — | Redhat Automation-controllerAIAnsible-coreAI | 9/23/2026 | 9/24/2026 | — | |
| Awaiting Analysis | Medium (5.3) | 0.34% | — | Redhat Ansible Automation ControllerAI | 9/23/2026 | 9/24/2026 | — | |
| Awaiting Analysis | High (7.6) | 0.31% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 9/23/2026 | 9/26/2026 | A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that omits process-hijacking loader variables such as BASH_ENV, ENV, LD_PRELOAD,… | |
| Awaiting Analysis | High (8.7) | 0.20% | — | Redhat Ansible Automation PlatformAI | 9/23/2026 | 9/24/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a live user object as an argument. Because Python string formatting permits attribute… | |
| Awaiting Analysis | High (8.7) | 0.26% | — | Redhat Ansible Automation PlatformAI | 9/23/2026 | 9/25/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacters but does not remove ANSI terminal escape sequences before conversion to HTML. An ANSI OSC 8 hyperlink sequence in the… | |
| Awaiting Analysis | Critical (9.1) | 0.41% | — | Redhat Ansible Automation PlatformAIRedhat AWXAI | 9/23/2026 | 9/24/2026 | A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service account token volumes. An AAP platform administrator can exploit this to escalate… | |
| Awaiting Analysis | Critical (9.9) | 0.62% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 9/23/2026 | 9/24/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the module runs git ls-remote with the URL as a positional argument and without a "--"… | |
| Awaiting Analysis | High (7.7) | 0.38% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 9/23/2026 | 9/26/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or workflow job template node is revalidated against a tightened survey specification, the controller… | |
| Awaiting Analysis | High (8.2) | 0.52% | — | Redhat Ansible Automation PlatformAI | 9/23/2026 | 9/24/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal task, dependency, and workflow schedulers are configured to allow any user (including unauthenticated clients) and are routed in production builds because their URL include is not gated on the… | |
| Awaiting Analysis | Critical (9.9) | 0.80% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 9/23/2026 | 9/24/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template API representation and in the activity stream -- and the provisioning callback… | |
| Awaiting Analysis | High (8.5) | 0.24% | — | Redhat AWXAI | 9/23/2026 | 9/26/2026 | CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC. The get() handler (lines 988–991) explicitly guards with request.user.can_access(obj._class_, 'read', obj) — but post() (lines 1001–1010) does not. POST only checks:… | |
| Awaiting Analysis | Medium (4.1) | 0.26% | — | Redhat Ansible Automation PlatformAI | 9/23/2026 | 9/24/2026 | — | |
| Awaiting Analysis | Medium (4.3) | 0.22% | — | Redhat RED HATAI | 9/23/2026 | 9/24/2026 | — | |
| Awaiting Analysis | Medium (6.2) | 0.13% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 9/23/2026 | 9/23/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rules Manager commands REST endpoint (`CommandsResource.java:31`). A local actor can invoke unauthenticated commands to cause resource exhaustionand halt business-rule management functions. | |
| Awaiting Analysis | High (8.2) | 0.30% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 9/23/2026 | 9/23/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database queries due to improper neutralization of special elements in a boolean expression. | |
| Awaiting Analysis | Medium (4.4) | 0.09% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 9/23/2026 | 9/23/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalation within the container due to improper privilege management. | |
| Awaiting Analysis | High (7.3) | 0.22% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 9/23/2026 | 9/23/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook upsert (CWE-74) in the FTM AI agent server (api.vectordb.runbooks.js:51). An unauthenticated attacker can insert malicious runbook content into the agent's vector database to steer AI-driven MCP tool… | |
| Awaiting Analysis | Critical (9.3) | 0.19% | — | IBM Financial Transaction ManagerAIRedhat OpenshiftAI | 9/23/2026 | 9/23/2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in the FTM UI NetworkAcknowledgement React component (NetworkAcknowledgement.jsx:42). A malicious actor can inject script into stored network acknowledgement data that executes in authenticated operator… |