Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 499
Alerts This Week
Warning Icon 1 499

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 129 articles for you...
87

Debian Oldstable php-twig Vulnerabilities for PHP Code Injection DSA-6320-1

Multiple security vulnerabilities were discovered in Twig, a template engine for PHP, which could result in PHP code injection, sandbox bypass or cross-site scripting. For the oldstable distribution (bookworm), these problems have been fixed in version 3.5.1-1+deb12u3.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6320-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff June 02, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : php-twig CVE ID : CVE-2024-51754 CVE-2026-46628 CVE-2026-46629 CVE-2026-46637 CVE-2026-47730 CVE-2026-46633 Multiple security vulnerabilities were discovered in Twig, a template engine for PHP, which could result in PHP code injection, sandbox bypass or cross-site scripting. For the oldstable distribution (bookworm), these problems have been fixed in version 3.5.1-1+deb12u3. We recommend that you upgrade your php-twig packages. For the detailed security status of php-twig please refer to its security tracker page at: https://security-tracker.debian.org/tracker/php-twig Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Multiple vulnerabilities in php-twig template engine could lead to code injection and cross-site attacks. Upgrade recommended.. Debian Security Advisory, PHP Template Engine, Twig Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 02, 2026 Critical Debian
87

Debian php-twig High Risk Code Injection XSS DSA-6320-1

Multiple security vulnerabilities were discovered in Twig, a template engine for PHP, which could result in PHP code injection, sandbox bypass or cross-site scripting. For the oldstable distribution (bookworm), these problems have been fixed in version 3.5.1-1+deb12u3.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6320-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff June 02, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : php-twig CVE ID : CVE-2024-51754 CVE-2026-46628 CVE-2026-46629 CVE-2026-46637 CVE-2026-47730 CVE-2026-46633 Multiple security vulnerabilities were discovered in Twig, a template engine for PHP, which could result in PHP code injection, sandbox bypass or cross-site scripting. For the oldstable distribution (bookworm), these problems have been fixed in version 3.5.1-1+deb12u3. We recommend that you upgrade your php-twig packages. For the detailed security status of php-twig please refer to its security tracker page at: https://security-tracker.debian.org/tracker/php-twig Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Discover multiple vulnerabilities in php-twig affecting Debian's oldstable release, requiring an upgrade for security.. Twig Template Engine, PHP Code Injection, Debian Security, Web Security, Cross-Site Scripting. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 02, 2026 Important Debian
219

Rocky Linux 8 RLSA-2026-11511 Nano Core Stability Vulnerability Patch

Important: vim security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:11509", "synopsis": "Important: vim security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for vim.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Vim (Vi IMproved) is an updated and improved version of the vi editor.\n\nSecurity Fix(es):\n\n* vim: arbitrary command execution via modeline sandbox bypass (CVE-2026-34982)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2455400", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2455400", "description": ""}], "cves": [{"name": "CVE-2026-34982", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34982", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N", "cvss3BaseScore": "8.2", "cwe": "CWE-78"}], "references": [], "publishedAt": "2026-04-30T18:00:45.302131Z", "rpms": {"Rocky Linux 8": {"nvras": ["vim-2:8.0.1763-22.el8_10.3.src.rpm", "vim-common-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-common-2:8.0.1763-22.el8_10.3.x86_64.rpm", "vim-common-debuginfo-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-common-debuginfo-2:8.0.1763-22.el8_10.3.x86_64.rpm", "vim-debuginfo-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-debuginfo-2:8.0.1763-22.el8_10.3.x86_64.rpm", "vim-debugsource-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-debugsource-2:8.0.1763-22.el8_10.3.x86_64.rpm", "vim-enhanced-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-enhanced-2:8.0.1763-22.el8_10.3.x86_64.rpm", "vim-enhanced-debuginfo-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-enhanced-debuginfo-2:8.0.1763-22.el8_10.3.x86_64.rpm","vim-filesystem-2:8.0.1763-22.el8_10.3.noarch.rpm", "vim-minimal-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-minimal-2:8.0.1763-22.el8_10.3.x86_64.rpm", "vim-minimal-debuginfo-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-minimal-debuginfo-2:8.0.1763-22.el8_10.3.x86_64.rpm", "vim-X11-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-X11-2:8.0.1763-22.el8_10.3.x86_64.rpm", "vim-X11-debuginfo-2:8.0.1763-22.el8_10.3.aarch64.rpm", "vim-X11-debuginfo-2:8.0.1763-22.el8_10.3.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A critical vim security update for Rocky Linux 8 addresses arbitrary command execution risks related to modeline sandbox bypass.. vim security update, Rocky Linux 8, command execution fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 30, 2026 Important Rocky Linux
197

Debian 11 SimpleEval Critical Sandbox Bypass Fix DLA-4543-1 CVE-2026-32640

Byambadalai Sumiya discovered that SimpleEval, a library for adding evaluatable expressions into Python projects, didn't fully restrict some module references, resulting in sandbox bypass. For Debian 11 bullseye, this problem has been fixed in version 0.9.10-1+deb11u1.. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4543-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Santiago Ruano Rincón April 21, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : simpleeval Version : 0.9.10-1+deb11u1 CVE ID : CVE-2026-32640 Debian Bug : 1130875 Byambadalai Sumiya discovered that SimpleEval, a library for adding evaluatable expressions into Python projects, didn't fully restrict some module references, resulting in sandbox bypass. For Debian 11 bullseye, this problem has been fixed in version 0.9.10-1+deb11u1. We recommend that you upgrade your simpleeval packages. For the detailed security status of simpleeval please refer to its security tracker page at: https://security-tracker.debian.org/tracker/simpleeval Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . SimpleEval library fixed sandbox bypass issue in Debian 11; vital security update available to maintain system integrity.. simpleeval security update,sandbox bypass patch,Debian LTS advisory,Python project security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 21, 2026 Critical Debian LTS
87

Debian DSA-6220-1 SimpleEval Important Sandbox Bypass CVE-2026-32640

Byambadalai Sumiya discovered that SimpleEval, a library for adding evaluatable expressions into Python projects, didn't fully restrict some module references, resulting in sandbox bypass. For the oldstable distribution (bookworm), this problem has been fixed in version 0.9.12-1+deb12u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6220-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 20, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : simpleeval CVE ID : CVE-2026-32640 Byambadalai Sumiya discovered that SimpleEval, a library for adding evaluatable expressions into Python projects, didn't fully restrict some module references, resulting in sandbox bypass. For the oldstable distribution (bookworm), this problem has been fixed in version 0.9.12-1+deb12u1. For the stable distribution (trixie), this problem has been fixed in version 1.0.3-1+deb13u1. We recommend that you upgrade your simpleeval packages. For the detailed security status of simpleeval please refer to its security tracker page at: https://security-tracker.debian.org/tracker/simpleeval Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Discover the Debian DSA-6220-1 advisory on SimpleEval sandbox bypass vulnerabilities and recommended updates.. Debian Security SimpleEval Sandbox Bypass Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 20, 2026 Important Debian
87

Debian DSA-6207-1 Flatpak Important Sandbox Breakout Exec Risk

Multiple security vulnerabilities were discovered in Flatpak, an application deployment framework for desktop apps, which could allow a Flatpak app to delete arbitrary hosts on the host or break out of the sandbox resulting in code execution in the host context. For the stable distribution (trixie), these problems have been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6207-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 12, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : flatpak CVE ID : CVE-2026-34078 CVE-2026-34079 Multiple security vulnerabilities were discovered in Flatpak, an application deployment framework for desktop apps, which could allow a Flatpak app to delete arbitrary hosts on the host or break out of the sandbox resulting in code execution in the host context. For the stable distribution (trixie), these problems have been fixed in version 1.16.6-1~deb13u1. We recommend that you upgrade your flatpak packages. For the detailed security status of flatpak please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/flatpak Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Multiple security issues in Flatpak may allow apps to delete hosts or execute code outside their sandbox. Upgrade recommended.. Flatpak Security Fixes, Debian DSA Advisories, Remote Code Execution Fixes, Application Sandbox Bypass. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 12, 2026 Important Debian
172

Ubuntu 24.04 LTS SimGear Important Exec Risk USN-7965-1 CVE-2025-0781

SimGear could be made to run programs as an administrator if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-7965-1 January 15, 2026 simgear vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: SimGear could be made to run programs as an administrator if it opened a specially crafted file. Software Description: - simgear: set of open-source libraries for assembling 3d simulations, games, and visualizations Details: It was discovered that SimGear could be made to bypass the sandboxing of Nasal scripts. An attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libsimgear-dev 1:2020.3.18+dfsg-2.1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS libsimgear-dev 1:2020.3.6+dfsg-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 20.04 LTS libsimgear-dev 1:2019.1.1+dfsg-3ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libsimgear-dev 1:2018.1.1+dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libsimgear-dev 3.4.0-3ubuntu0.1~esm1 Available with Ubuntu Pro libsimgearcore3.4.0v5 3.4.0-3ubuntu0.1~esm1 Available with Ubuntu Pro libsimgearscene3.4.0v5 3.4.0-3ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7965-1 CVE-2025-0781 . A SimGear vulnerability allows potential code execution via crafted files, requiring a security update for Ubuntu systems.. SimGear Security Update, Ubuntu 24.04 LTS Review, Code Execution Risk. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 15, 2026 Important Ubuntu
197

Debian 11: OpenJDK 11 Important Security Advisory DLA-4248-1 CVE-2025-30749

Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service, information disclosure or bypass of sandbox restrictions. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4248-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort July 23, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : openjdk-11 Version : 11.0.28+6-1~deb11u1 CVE ID : CVE-2025-30749 CVE-2025-30754 CVE-2025-30761 CVE-2025-50059 CVE-2025-50106 Several vulnerabilities have been discovered in the OpenJDK Java runtime, which may result in denial of service, information disclosure or bypass of sandbox restrictions. For Debian 11 bullseye, these problems have been fixed in version 11.0.28+6-1~deb11u1. We recommend that you upgrade your openjdk-11 packages. For the detailed security status of openjdk-11 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/openjdk-11 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Essential patches for OpenJDK 11 released to mitigate denial of service and data leakage security flaws on Debian platforms.. Debian Updates, OpenJDK Security, Java Runtime Vulnerability, System Upgrade Recommendations. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 23, 2025 Important Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200