Security advisories (VSA)
All published Vates Security Advisories, one page per advisory with the impact, affected versions, mitigation and the packages fixing the issue. Search by VSA identifier, CVE or XSA number, or filter by severity, product and year; you can also browse by year in the sidebar.
32 advisories, showing 1-10
| Advisory | Published | Severity | Affected products | References |
|---|---|---|---|---|
| VSA-2026-023XAPI Missing TLS verification in some SDKs (CVE-2026-42491 / XSA-498) | 2026-07-15 | N/A | None (SDK not used) | XSA-498, CVE-2026-42491 |
| VSA-2026-022LLDPD vulnerability in VLAN decapsulation | 2026-06-23 | Low | XCP-ng 8.3 | CVE-2026-46433 |
| VSA-2026-021Linux Kernel CIFS Client Local Privilege Escalation (CVE-2026-46243) | 2026-06-10updated 2026-06-23 | Moderate | XCP-ng, XOA | CVE-2026-46243 |
| VSA-2026-020x86 mismatched mapcache metadata (XSA-494) | 2026-06-10updated 2026-06-23 | N/A | None (PV only) | XSA-494, CVE-2026-42488 |
| VSA-2026-019Arm TLBI completion issue (XSA-493) | 2026-06-10 | N/A | None (Arm only) | XSA-493, CVE-2025-10263 |
| VSA-2026-018domctl lock open to abuse (XSA-492) | 2026-06-10updated 2026-06-23 | Low | XCP-ng 8.3 | XSA-492, CVE-2026-42489, CVE-2026-42490 |
| VSA-2026-017x86 HVM I/O port list traversal (XSA-491) | 2026-06-10updated 2026-06-23 | Low | XCP-ng 8.3 | XSA-491, CVE-2026-42487 |
| VSA-2026-016Linux Kernel ptrace and RDS Local Privilege Escalation (CVE-2026-46333, CVE-2026-43494) | 2026-06-02 | Moderate | XCP-ng, XOA | CVE-2026-46333, CVE-2026-43494 |
| VSA-2026-015x86 CPU Opcode Cache corruption (XSA-490) | 2026-05-21 | Critical | XCP-ng 8.3 | XSA-490, CVE-2025-54518 |
| VSA-2026-014Linux Kernel XFRM/RXRPC Local Privilege Escalation (CVE-2026-43284, CVE-2026-43500, CVE-2026-46300) | 2026-05-15updated 2026-06-02 | Moderate | XCP-ng, XOA | CVE-2026-43284, CVE-2026-43500, CVE-2026-46300 |
Page 1 of 4
Subscribe
Security teams can follow VSA publications without watching this page:
- RSS feed: /vsa/rss.xml
- Machine-readable index: /vsa/index.json, the same data that powers the list above, for scripts and vulnerability management tooling.
Was this page helpful?