Security Advisory – 24 Apr 2026

Security fixes and advisories that landed overnight. Two notices are included below, grouped by source and kept to the facts. The update below reflects notices published within the current review period. Updated 24 Apr 2026 00:00 GMT.

Top items

Ubuntu

USN-8180-5: Linux kernel (IBM) vulnerabilities

Several security issues were discovered in the Linux kernel. The update corrects flaws across multiple subsystems, including networking, filesystems, Bluetooth, and TLS.

  • Published: 24 Apr 2026 09:40 GMT
  • CVEs: CVE-2023-53421, CVE-2023-53520, CVE-2023-53662, CVE-2023-54207, CVE-2025-38057, CVE-2025-38125, CVE-2025-38232, CVE-2025-38408, CVE-2025-38591, CVE-2025-40149, CVE-2025-40164, CVE-2025-68211, CVE-2025-68340, CVE-2025-68365, CVE-2025-68725, CVE-2025-68817, CVE-2025-71162, CVE-2025-71163, CVE-2025-71185, CVE-2025-71186, CVE-2025-71188, CVE-2025-71190, CVE-2025-71191, CVE-2025-71194, CVE-2025-71196, CVE-2025-71197, CVE-2025-71199, CVE-2026-22997, CVE-2026-22998, CVE-2026-22999, CVE-2026-23001, CVE-2026-23003, CVE-2026-23011, CVE-2026-23026, CVE-2026-23033, CVE-2026-23037, CVE-2026-23038, CVE-2026-23049, CVE-2026-23056, CVE-2026-23058, CVE-2026-23061, CVE-2026-23063, CVE-2026-23064, CVE-2026-23071, CVE-2026-23073, CVE-2026-23075, CVE-2026-23076, CVE-2026-23078, CVE-2026-23080, CVE-2026-23083, CVE-2026-23084, CVE-2026-23085, CVE-2026-23087, CVE-2026-23089, CVE-2026-23090, CVE-2026-23091, CVE-2026-23093, CVE-2026-23095, CVE-2026-23096, CVE-2026-23097, CVE-2026-23098, CVE-2026-23099, CVE-2026-23101, CVE-2026-23103, CVE-2026-23105, CVE-2026-23108, CVE-2026-23119, CVE-2026-23120, CVE-2026-23121, CVE-2026-23124, CVE-2026-23125, CVE-2026-23128, CVE-2026-23133, CVE-2026-23145, CVE-2026-23146, CVE-2026-23150, CVE-2026-23164, CVE-2026-23167, CVE-2026-23170, CVE-2026-23209
  • Notes: An attacker could possibly use these to compromise the system

NIST

CVE-2026-29198

Rocket.Chat versions before 8.3.0, 8.2.1, 8.1.2, 8.0.3, 7.13.5, 7.12.6, 7.11.6, and 7.10.9 are affected by a NoSQL injection issue. The flaw can lead to account takeover of the first user with a generated token when an OAuth app is configured.

  • Published: 23 Apr 2026 00:16 GMT
  • CVEs: CVE-2026-29198
  • Notes: NoSQL injection vulnerability

Related posts

Talos Linux | v1.12.7

Talos Linux v1 12 7: kernel 6 18 24, containerd 2 1 7, Go 1 25 9, Kubernetes 1 35 4, etcd 3 6 9, AppArmor, TPM and tooling updates, bug and test fixes

HomeAssistant Core | 2026.4.4

Home Assistant Core 2026 4 4: integration fixes, auth and API validation hardening, dependency and frontend updates for improved reliability and compatibility

Security Advisory – 24 Apr 2026

Daily security advisory summary for 24 Apr 2026