April 2026 - Page 149 of 170

Windows Server 2019 — KB5058429 — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on Windows Server 2019

Windows Server 2019 — KB5058429 — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🔴 Critical   ⏱ 15–90 min  Last verified: 25 May 2026 Affected versions: Windows Server 2019 📖 ~4 min read  •  Source: Microsoft KB5058429 • MSRC update-guide entry Related CVEs: CVE-2025-32710 CVE-2025-47955 CVE-2025-29959 CVE-2025-29960 CVE-2025-29968 CVE-2025-29969 CVE-2025-32701 CVE-2025-32706  +12 more Affected components: Windows Server 2019 (Server Core installation) Microsoft summary: Use after free in Windows […]

Read more
Amazon Linux 2 — openssh — multiple vulnerabilities (15 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — openssh — multiple vulnerabilities (15 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2-2026-3262 Related CVEs: CVE-2026-35385 CVE-2016-10009 CVE-2023-38408 CVE-2025-26465 CVE-2023-51385 CVE-2023-48795 CVE-2019-6111 CVE-2023-35812  +7 more Upstream summary: In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, […]

Read more
Amazon Linux 2 — kernel-livepatch-5.10.252-250.992 — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on Amazon Linux 2

Amazon Linux 2 — kernel-livepatch-5.10.252-250.992 — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Amazon Linux 2 📖 ~4 min read  •  Source: Amazon Linux advisory ALAS2LIVEPATCH-2026-289 Related CVEs: CVE-2026-43284 CVE-2026-31431 Upstream summary: In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags "Dirty Frag" and other […]

Read more
AlmaLinux 8 — xorg-x11-server-Xwayland — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on AlmaLinux 8

AlmaLinux 8 — xorg-x11-server-Xwayland — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: AlmaLinux 8 📖 ~4 min read  •  Source: AlmaLinux ALSA ALSA-2026:11656 Related CVEs: CVE-2026-33999 CVE-2026-34001 CVE-2026-34003 CVE-2025-49175 CVE-2025-49176 CVE-2025-49178 CVE-2025-49179 CVE-2025-49180  +12 more Upstream summary: Xwayland is an X server for running X clients under Wayland. Security Fix(es): * xorg: xwayland: X.Org […]

Read more
Rocky Linux 8 — sudo — vulnerability — patch and remediation guide — diagnosis and fix on Rocky Linux 8

Rocky Linux 8 — sudo — vulnerability — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: Rocky Linux 8 📖 ~4 min read  •  Source: Rocky Linux RXSA RLSA-2026:11521 Related CVEs: CVE-2026-35535 Upstream summary: The sudo packages contain the sudo utility which allows system administrators to provide certain users with the permission to execute privileged commands, which are […]

Read more
AlmaLinux 8 — libtiff — multiple vulnerabilities (20 CVEs) — patch and remediation guide — diagnosis and fix on AlmaLinux 8

AlmaLinux 8 — libtiff — multiple vulnerabilities (20 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: AlmaLinux 8 📖 ~4 min read  •  Source: AlmaLinux ALSA ALSA-2026:16055 Related CVEs: CVE-2026-4775 CVE-2025-8176 CVE-2025-9900 CVE-2017-17095 CVE-2024-7006 CVE-2018-15209 CVE-2023-25433 CVE-2023-52356  +12 more Upstream summary: The libtiff packages contain a library of functions for manipulating Tagged Image File Format (TIFF) files. Security […]

Read more
FreeBSD 15 — libgd — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — libgd — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: libgd — Denial of servica via double free Related CVEs: CVE-2017-6362 CVE-2017-7890 Upstream summary: libgd developers report: Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote […]

Read more
FreeBSD 15 — rubygem-rest-client — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 15

FreeBSD 15 — rubygem-rest-client — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 15 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: rest-client — plaintext password disclosure Related CVEs: CVE-2015-1820 CVE-2015-3448 Upstream summary: The open sourced vulnerability database reports: REST Client for Ruby contains a flaw that is due to the application […]

Read more
FreeBSD 14 — postgresql16-client — multiple vulnerabilities (17 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 14

FreeBSD 14 — postgresql16-client — multiple vulnerabilities (17 CVEs) — patch and remediation guide

🟠 High   ⏱ 15–60 min  Last verified: 25 May 2026 Affected versions: FreeBSD 14 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: PostgreSQL — Multiple vulnerabilities Related CVEs: CVE-2024-10977 CVE-2024-7348 CVE-2025-1094 CVE-2025-12817 CVE-2025-12818 CVE-2025-4207 CVE-2026-6472 CVE-2026-6473  +9 more Upstream summary: The PostgreSQL project reports: Missing authorization in PostgreSQL CREATE TYPE allows an […]

Read more
FreeBSD 12 — py311-social-auth-app-django — multiple vulnerabilities (2 CVEs) — patch and remediation guide — diagnosis and fix on FreeBSD 12

FreeBSD 12 — py311-social-auth-app-django — multiple vulnerabilities (2 CVEs) — patch and remediation guide

🟢 Low   ⏱ 5–15 min  Last verified: 25 May 2026 Affected versions: FreeBSD 12 📖 ~4 min read  •  Source: FreeBSD VuXML VuXML topic: py-social-auth-app-django — Unsafe account association Related CVEs: CVE-2024-32879 CVE-2025-61783 Upstream summary: Michal Čihař reports: Upon authentication, the user could be associated by e-mail even if the associate_by_email pipeline was not […]

Read more
CHAT