Skip to content
VulniPulse

Red Hat Linux Red Hat Enterprise Linux Vulnerabilities & Security Advisories

1225 advisories tracked · Red Hat Security Data API · 3 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Red Hat Linux advisory that VulniPulse classified as Red Hat Enterprise Linux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 31 critical, 785 high, 384 medium, 25 low.

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux Red Hat Enterprise Linux advisories

High7.5Linux Updated

High [CVE-2026-16368] Incorrect boundary conditions in the JavaScript: WebAssembly component

Incorrect boundary conditions in the JavaScript: WebAssembly component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16368
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Vendor: MediumLinux Updated

High [CVE-2026-16354] Information disclosure in the Graphics: ImageLib component

Information disclosure in the Graphics: ImageLib component. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-201. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16354
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Vendor: MediumLinux Updated

High [CVE-2026-16353] Invalid pointer in the DOM: Bindings (WebIDL) component

Invalid pointer in the DOM: Bindings (WebIDL) component. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16353
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Linux Updated

High [CVE-2026-16363] JIT miscompilation in the JavaScript: WebAssembly component

JIT miscompilation in the JavaScript: WebAssembly component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-733. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16363
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Linux Updated

High [CVE-2026-16352] Sandbox escape due to use-after-free in the Disability Access APIs component

Sandbox escape due to use-after-free in the Disability Access APIs component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16352
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Linux Updated

High [CVE-2026-16351] Sandbox escape due to use-after-free in the DOM: Navigation component

Sandbox escape due to use-after-free in the DOM: Navigation component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16351
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Linux Updated

High [CVE-2026-16362] Use-after-free in the WebRTC: Audio/Video component

Use-after-free in the WebRTC: Audio/Video component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16362
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Vendor: MediumLinux Updated

High [CVE-2026-16350] Incorrect boundary conditions in the Audio/Video: cubeb component

Incorrect boundary conditions in the Audio/Video: cubeb component. Red Hat rates this moderate (CVSS 7.5). Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16350
Red Hat Enterprise Linux
Jul 21, 2026
High7.5Linux Updated

High [CVE-2026-16349] Same-origin policy bypass in the DOM: Navigation component

Same-origin policy bypass in the DOM: Navigation component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-346. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16349
Red Hat Enterprise Linux
Jul 21, 2026
High8.2Linux Updated

High [CVE-2026-60315] X Plugin unspecified vulnerability (CPU Jul 2026)

Oracle CPU describes the issue as following: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster and unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update. Red Hat severity: Important — CVSS 8.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H). Weakness: CWE-248. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-60315
Red Hat Enterprise Linux
Jul 21, 2026
High8.4Linux Updated

High [CVE-2026-60163] Group Replication Plugin unspecified vulnerability (CPU Jul 2026)

Oracle CPU describes the issue as following: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update. Red Hat severity: Important — CVSS 8.4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-266. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-60163
Red Hat Enterprise Linux
Jul 21, 2026
High7.2Linux Updated

High [CVE-2026-61094] Replication unspecified vulnerability (CPU Jul 2026)

Oracle CPU describes the issue as following: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update. Red Hat severity: Important — CVSS 7.2 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-266. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-61094
Red Hat Enterprise Linux
Jul 21, 2026
High7.2Linux Updated

High [CVE-2026-60316] X Plugin unspecified vulnerability (CPU Jul 2026)

Oracle CPU describes the issue as following: Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: X Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. Red Hat Product Security rates the severity of this flaw as determined by the Oracle MySQL Critical Patch Update. Red Hat severity: Important — CVSS 7.2 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-648. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-60316
Red Hat Enterprise Linux
Jul 21, 2026
Medium5.3Linux Updated

Medium [CVE-2026-46917] Improve DTLS handshaking (Oracle CPU 2026-07)

Improve DTLS handshaking (Oracle CPU 2026-07). Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:42895 with package java-25-openjdk-1:25.0.4.0.7-1.1.el10_2, java-21-openjdk-1:21.0.12.0.8-1.1.el8, java-21-openjdk-1:21.0.12.0.8-1.1.el9, java-25-openjdk-windows. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.

CVE-2026-46917
Red Hat Enterprise Linux
Jul 21, 2026
Medium5.3Linux Updated

Medium [CVE-2026-47021] Enhance XBM image support (Oracle CPU 2026-07)

Enhance XBM image support (Oracle CPU 2026-07). Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:42895 with package java-21-openjdk-1:21.0.12.0.8-1.1.el8, java-21-openjdk-1:21.0.12.0.8-1.1.el9, java-25-openjdk-windows, java-11-openjdk-1:11.0.32.0.9-1.el9. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-47021
Red Hat Enterprise Linux
Jul 21, 2026
Medium5.3Linux Updated

Medium [CVE-2026-47027] Enhance Jar file processing (Oracle CPU 2026-07)

Enhance Jar file processing (Oracle CPU 2026-07). Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:42895 with package java-21-openjdk-1:21.0.12.0.8-1.1.el8, java-21-openjdk-1:21.0.12.0.8-1.1.el9, java-25-openjdk-windows, java-11-openjdk-1:11.0.32.0.9-1.el9. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-47027
Red Hat Enterprise Linux
Jul 21, 2026
Medium6.5Linux Updated

Medium [CVE-2026-60147] Improve certification checking (Oracle CPU 2026-07)

Improve certification checking (Oracle CPU 2026-07). Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:42895 with package java-21-openjdk-1:21.0.12.0.8-1.1.el8, java-21-openjdk-1:21.0.12.0.8-1.1.el9, java-25-openjdk-windows, java-11-openjdk-1:11.0.32.0.9-1.el9. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-60147
Red Hat Enterprise Linux
Jul 21, 2026
Medium4.2Linux

Medium [CVE-2026-12548] Libsoup: heap out-of-bounds read in libsoup due to integer truncation

A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause the length parameter to be incorrectly truncated, leading to a heap buffer over-read. A remote attacker could use this flaw to crash an application using libsoup or potentially disclose heap memory contents. Red Hat severity: Moderate — CVSS 4.2 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-12548
Red Hat Enterprise Linux
Jul 21, 2026
Medium6.1Linux Updated

Medium [CVE-2026-16396] Privilege escalation in WebExtensions

Privilege escalation in WebExtensions. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8.

CVE-2026-16396
Red Hat Enterprise Linux
Jul 21, 2026
Medium6.1Linux Updated

Medium [CVE-2026-16394] Mitigation bypass in the DOM: Security component

A flaw was found in Firefox and Thunderbird. The Mozilla Foundation's Security Advisory describes the following issue: Mitigation bypass in the DOM: Security component Red Hat Product Security rates the severity of this flaw as determined by the Mozilla Foundation Security Advisory. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Weakness: CWE-358. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-16394
Red Hat Enterprise Linux
Jul 21, 2026

← All Linux advisories