Skip to main content

Threats Tagged 'microsoft-security-response-ce'

View all threats tagged with 'microsoft-security-response-ce'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: microsoft-security-response-ce

Threats Tagged 'microsoft-security-response-ce'

Click on any threat for detailed analysis and mitigation recommendations

Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. This advisory contains the container images for Red Hat OpenShift Container Platform 4.22.15. See the following advisory for the RPM packages for this release: https://access.redhat.com/errata/RHSA-2026:68550 Space precludes documenting all of the container images in this advisory. See the following Release Notes documentation, which will be updated shortly for this release, for details about these changes: https://docs.redhat.com/en/documentation/openshift_container_platform/4.22/html/release_notes/

Join the discussion

Git Large File Storage (LFS) replaces large files such as audio samples, videos, datasets, and graphics with text pointers inside Git, while storing the file contents on a remote server. Security Fix(es): * crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) * golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion
0

These are all security issues fixed in the kernel-devel-7.2.9-1.1 package on the GA media of openSUSE Tumbleweed.

Join the discussion

This update for the SUSE Linux Enterprise Kernel 6.4.0-49.1 fixes various security issues: The following security issues were fixed: - CVE-2026-63802: blk-cgroup: fix UAF in __blkcg_rstat_flush() (bsc#1272283). - CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272391). - CVE-2026-63912: xfrm: esp: restore combined single-frag length gate (bsc#1272837). - CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink() (bsc#1273015). - CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1273012). - CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (bsc#1273011). - CVE-2026-63944: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (bsc#1273003). - CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff (bsc#1272679). - CVE-2026-63994: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() (bsc#1273051). - CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273052). - CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273833). - CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273837). - CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list resize (bsc#1272208). - CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1275228). - CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275162). - CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277409). - CVE-2026-74612: veth: fix skb length accounting after XDP frag adjustment (bsc#1277506).

Join the discussion
0

To determine the support lifecycle for your software, see the Microsoft Support Lifecycle: https://support.microsoft.com/lifecycle

Join the discussion

Red Hat Edge Manager (RHEM) provides simple, scalable, and security-focused management of edge devices and applications. It supports image-mode RHEL and container workloads that run on Podman/Docker or Kubernetes. RHEM is now available as a standalone feature, providing greater flexibility for edge deployments. In addition to the standalone version, RHEM continues to be offered as a plugin for the following platforms: Red Hat Advanced Cluster Management (RHACM): Extends fleet management to edge devices. Red Hat Ansible Automation Platform (AAP): Integrates edge management with Ansible automation. This integration enables organizations to optimize the management and orchestration of their fleets of edge devices; whether its thousands of dispersed retail point-of-sale systems or industrial machinery on remote factory floors. Value for customers and partners: * This solution not only helps customers manage thousands of devices but helps scale operations. * To manage large-scale deployments, customers need to be able to integrate with their existing management systems, support remote configuration and over-the-air updates, and collect telemetry data for advanced analytics. * Red Hat Edge Manager offers a simple and security-focused lifecycle management, from onboarding to decommissioning of edge devices. This complete end-to-end solution empowers organizations to gain the most value from the fleets of devices that generate data, all from a centralized location. Security Fixes: * flightctl: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) * flightctl: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * flightctl: OpenTelemetry-Go: Denial of Service via oversized baggage headers (CVE-2026-41178) * flightctl: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740) * flightctl: Arc: Information disclosure and Denial of Service via unauthenticated debug endpoints (CVE-2026-48050) * flightctl: golang.org/x/text: Denial of Service via invalid UTF-8 input (CVE-2026-56852) * flightctl: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * flightctl: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * flightctl: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) * flightctl: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * flightctl: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * flightctl: go-git: Arbitrary file read/write via symbolic link resolution (CVE-2026-71556)

Join the discussion

Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library. This release of Red Hat JBoss Web Server 6.2.5 serves as a replacement for Red Hat JBoss Web Server 6.2.4. This release includes bug fixes, enhancements and component upgrades, which are documented in the Release Notes that are linked to in the References section. Security Fix(es): * tomcat-catalina: Apache Tomcat: Misleading security logs due to incorrect control flow (CVE-2026-55276) * tomcat-coyote-ffm: Apache Tomcat: Error condition not handled when configuring CRL (CVE-2026-53434) * jws6-tomcat: Apache Tomcat: Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083) * tomcat: Apache Tomcat: Local information disclosure via Unix domain socket TOCTOU race condition (CVE-2026-65183) * tomcat: Apache Tomcat: Security constraint bypass due to improper access control (CVE-2026-65182) * tomcat: Apache Tomcat: Access control bypass due to off-by-one error in RewriteValve [N] flag processing (CVE-2026-65927) * tomcat: Apache Tomcat: Denial of Service via HTTP/2 allocation leak (CVE-2026-68763) * tomcat: Apache Tomcat: Unauthorized resource access via FORM authentication bypass (CVE-2026-68525) * tomcat: Apache Tomcat - DoS in WebSocket chat example (CVE-2026-66299) * tomcat: Apache Tomcat: Authenticated WebSocket session persists after HTTP session termination (CVE-2026-73180) * tomcat: Apache Tomcat: Improper Authorization allows bypass of declarative role constraints (CVE-2026-66422) * tomcat: Apache Tomcat: Improper Authentication due to principal lookup failure (CVE-2026-68569) * tomcat: Apache Tomcat: Authentication bypass via limited replay attack in DIGEST authenticator (CVE-2026-65905) * openssl.exe: Heap Use-After-Free in OpenSSL PKCS7_verify() (CVE-2026-45447) * jws-optional-native-components-win6-x86_64.zip: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys (CVE-2026-34181) * jws-optional-native-components-win6-x86_64.zip: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure (CVE-2026-34180) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Join the discussion

Red Hat has released an update for the OpenShift File Integrity Operator (v1.5.0) that addresses multiple bugs and includes enhancements. This update fixes several security vulnerabilities including CVE-2026-56853. The advisory indicates the update is important and should be applied after ensuring all prior relevant errata are installed. The update includes schema extensions, network policy improvements, TLS profile consistency, and a base image switch. The vulnerability is rated as high severity.

Join the discussion

The 3.30.1 release fixes the regression CRW-13015 Get Started / sample cards on the dashboard are empty after upgrade to 3.30. This release provides additional CVE fixes and container dependency updates to Dev Spaces 3.30. Red Hat OpenShift Dev Spaces provides a cloud developer workspace server and a browser-based IDE built for teams and organizations. Dev Spaces runs in OpenShift and is well-suited for container-based development. The 3.30 release is based on Eclipse Che 7.121 and uses the DevWorkspace engine to provide support for workspaces based on devfile v2.1 and v2.2. Users still using the v1 standard should migrate as soon as possible. https://devfile.io/docs/2.2.0/migrating-to-devfile-v2 Dev Spaces supports OpenShift EUS releases v4.16 and higher. Users are expected to update to supported OpenShift releases in order to continue to get Dev Spaces updates. https://access.redhat.com/support/policy/updates/openshift#crw

Join the discussion

Showing 1 to 10 of 1303 results

Filters:Tag: microsoft-security-response-ce
Page 1 of 131
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses