Fedora Security Advisories

cockpit-machines-357-1.fc45

4 days 14 hours ago
FEDORA-2026-2afda0f514 Packages in this update:
  • cockpit-machines-357-1.fc45
Update description:

Automatic update for cockpit-machines-357-1.fc45.

Changelog for cockpit-machines * Wed Sep 23 2026 Packit <hello@packit.dev> - 357-1 - Harden against local attacks from accessing sensitive data CVE-2026-92768, CVE-2026-92747, CVE-2026-92745 - Resolves RHEL-263125, RHEL-263121, RHEL-263122 for rhel-10.4 - Resolves RHEL-263116, RHEL-263119, RHEL-263126 for rhel-9.10

cockpit-files-45-1.fc43

4 days 14 hours ago
FEDORA-2026-a643ae21d6 Packages in this update:
  • cockpit-files-45-1.fc43
Update description:

Automatic update for cockpit-files-45-1.fc43.

Changelog for cockpit-files * Wed Sep 23 2026 Packit <hello@packit.dev> - 45-1 - Fixes CVE-2026-91202, CVE-2026-91203, CVE-2026-91205 - Resolves RHEL-263138, RHEL-263139, RHEL-263144 for rhel-10.4 - Resolves RHEL-263135, RHEL-263137, RHEL-263145 for rhel-9.10

emacs-31.1-4.fc46

4 days 15 hours ago
FEDORA-2026-b3367f2111 Packages in this update:
  • emacs-31.1-4.fc46
Update description:

Automatic update for emacs-31.1-4.fc46.

Changelog * Wed Sep 23 2026 Peter Oliver <git@mavit.org.uk> - 1:31.1-4 - Prevent arbitrary code execution in flymake (rhbz#2537390).

hplip-3.26.6-1.fc43

4 days 16 hours ago
FEDORA-2026-59a4f90bc0 Packages in this update:
  • hplip-3.26.6-1.fc43
Update description:

3.26.6, fixes CVE-2026-91105,CVE-2026-91103,CVE-2026-91102,CVE-2026-91101,

CVE-2026-91100,CVE-2026-91099,CVE-2026-91098,CVE-2026-91097

hplip-3.26.6-1.fc44

4 days 16 hours ago
FEDORA-2026-9e80aed94f Packages in this update:
  • hplip-3.26.6-1.fc44
Update description:

3.26.6, fixes CVE-2026-91105,CVE-2026-91103,CVE-2026-91102,CVE-2026-91101,

CVE-2026-91100,CVE-2026-91099,CVE-2026-91098,CVE-2026-91097

hplip-3.26.6-1.fc45

4 days 17 hours ago
FEDORA-2026-ebccf08143 Packages in this update:
  • hplip-3.26.6-1.fc45
Update description:

3.26.6, fixes CVE-2026-91105,CVE-2026-91103,CVE-2026-91102,CVE-2026-91101,

CVE-2026-91100,CVE-2026-91099,CVE-2026-91098,CVE-2026-91097

wordpress-6.9.9-1.fc44

5 days 1 hour ago
FEDORA-2026-7f9c69a63c Packages in this update:
  • wordpress-6.9.9-1.fc44
Update description: WordPress 6.9.9 Security Release

Security updates included in this release

  • Unauthenticated path traversal in page-template resolution leading to conditional RCE CVE-2026-87902
WordPress 6.9.8 Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.

wordpress-6.9.9-1.el10_2

5 days 1 hour ago
FEDORA-EPEL-2026-fa7b2ec3a3 Packages in this update:
  • wordpress-6.9.9-1.el10_2
Update description: WordPress 6.9.9 Security Release

Security updates included in this release

  • Unauthenticated path traversal in page-template resolution leading to conditional RCE CVE-2026-87902
WordPress 6.9.8 Security Release

Security updates included in this release

  • Stored cross-site scripting in wpautop() allows an unauthenticated visitor to inject script (subject to comment approval), reported by Rafie Muhammad (Awesome Motive, Inc.).
  • HTML API: set_modifiable_text() allows breaking out of a comment via abrupt-closing sequences, reported by Jeremy Felt of the WordPress Security Team.
  • Stored XSS in some themes that support custom headers, reported by Jeremy Felt of the WordPress Security Team.
  • Specially crafted URLs can automatically install and preview an inactive theme from WordPress.org, reported by Paulos Yibelo and pwn.ai.
  • Site Administrator can network-activate an installed Network-only plugin, reported by Jesse McNeil.
  • Authenticated Path Traversal in WP REST Templates Controller, reported by Anthropic.
  • XML-RPC can be used to publish customize_changeset posts that bypass checks for edit_css, reported by Ben Bidner of the WordPress Security Team.
  • Contributor+ Arbitrary Post Overwrite, reported by Anthropic.
  • Missing read_post check in attachment_submitbox_metadata() leaks a private parent-post title, reported by HDWSec.
  • Missing Authorization leads to Draft/Pending Post Slug Disclosure by Contributor+, reported by hermanhms.
  • Comments, including notes, can be reparented by any authenticated user, reported by viridis.
Checked
1 minute 19 seconds ago