Critical Vulnerabilities in Tigervnc Affect Oracle and Rocky Linux Users

Critical Vulnerabilities in Tigervnc Affect Oracle and Rocky Linux Users

First seen 25 Jun 2026, 12:08 UTC Linuxsecurity 79% similarity 74.0
Share:

Article Content

Browse articles
ThreatCluster

Recent updates for Tigervnc have addressed multiple critical vulnerabilities affecting Oracle Linux 9 and Rocky Linux 8. The vulnerabilities include CVE-2026-33999, CVE-2026-34000, CVE-2026-34001, CVE-2026-34002, and CVE-2026-34003, which were published between April and May 2026. These vulnerabilities can lead to remote access issues and potential exploitation of systems. Oracle Linux 9 users are urged to update to version 1.15.0-7.1, while Rocky Linux 8 users should upgrade to version 1.15.0-10. The updates include fixes for various XKB and XSYNC vulnerabilities, use-after-free issues, and integer overflows. The CVSS scores for these vulnerabilities indicate a high severity, emphasizing the need for immediate action. Administrators are advised to apply these updates promptly to mitigate risks.

Key Points: • Multiple critical vulnerabilities in Tigervnc affect Oracle and Rocky Linux systems. • Affected CVEs include CVE-2026-33999, CVE-2026-34000, and others with high CVSS scores. • Immediate updates are recommended for both Oracle Linux 9 and Rocky Linux 8 users.

ThreatCluster AI

Timeline

2025-06-17
CVE-2025-49176 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-06-17
CVE-2025-49175 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-06-17
CVE-2025-49178 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-10-30
CVE-2025-62231 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-10-30
CVE-2025-62229 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-10-30
CVE-2025-62230 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-03-26
CVE-2026-34352 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-23
CVE-2026-33999 published
A critical vulnerability in Tigervnc was disclosed, affecting remote access functionalities.
Linuxsecurity
2026-04-23
CVE-2026-34003 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-23
CVE-2026-34001 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

Community

Browse all →