Red Hat Linux Security Advisories & CVEs
11553 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-90202] Avoid freeing unallocated PCIe SGL buffers
Avoid freeing unallocated PCIe SGL buffers. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.
Low [CVE-2026-93378] Missing authorization in Storage
Missing authorization in Storage. Red Hat rates this low (CVSS 3). Weakness: CWE-653.
Low [CVE-2026-85716] Server impersonation due to unverified authentication responses
Server impersonation due to unverified authentication responses. Red Hat rates this low (CVSS 3.7). Weakness: CWE-347. Affected product named by the advisory: Red Hat Fuse 7.
Low [CVE-2026-92962] Information disclosure via stack trace interception
Information disclosure via stack trace interception. Red Hat rates this low (CVSS 2.5). Weakness: CWE-915.
Critical [CVE-2026-92828] Operator ServiceAccount bound to cluster-admin
Operator ServiceAccount bound to cluster-admin. Red Hat rates this important (CVSS 9). Weakness: CWE-250. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.
Critical [CVE-2026-59969] Improper certificate validation in FIPS mode allows quorum compromise
Improper certificate validation in FIPS mode allows quorum compromise. Red Hat rates this important (CVSS 9). Weakness: CWE-295. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat build of Apache Camel for Spring Boot 4; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 2 more. Affected products named by the advisory: Red Hat Offline Knowledge Portal; Red Hat OpenShift AI (RHOAI).
Critical [CVE-2026-81642] Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY
Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-122. Red Hat lists fixing advisory RHSA-2026:71419 with package unbound-0:1.6.6-5.el7_9.2, unbound-0:1.16.2-3.el9_2.6, unbound-0:1.16.2-8.el9_4.3, unbound-0:1.16.2-19.el9_6.2. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.
High [CVE-2026-92599] Denial of Service via `isoDate` validation regular expression
Denial of Service via `isoDate` validation regular expression. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:68778 with package grafana13-2-main-13.2.1-0.5.hum1, grafana13-1-main-13.1.6-0.2.hum1, grafana12-4-main-12.4.10-0.6.hum1. Affected products named by the advisory: Red Hat Hardened Images; Gatekeeper 3; Migration Toolkit for Containers; Red Hat Data Grid 8; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; and 1 more.
High [CVE-2026-92596] Denial of Service in addressparser component
Denial of Service in addressparser component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Affected product named by the advisory: Self-service automation portal 2.
High [CVE-2026-85469] Release workflow uses third-party Action pinned to mutable @master with registry credentials in scope
Release workflow uses third-party Action pinned to mutable @master with registry credentials in scope. Red Hat rates this important (CVSS 8). Weakness: CWE-1357. Affected product named by the advisory: Red Hat Quay 3.
High [CVE-2026-92786] Out-of-bounds write via crafted model file
Out-of-bounds write via crafted model file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).
High [CVE-2026-91106] heap-based buffer overflow can lead to remote code execution
heap-based buffer overflow can lead to remote code execution. Red Hat rates this important (CVSS 8.4). Weakness: CWE-122. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.
High [CVE-2026-91105] Remote code execution and privilege escalation vulnerabilities
Remote code execution and privilege escalation vulnerabilities. Red Hat rates this important (CVSS 8.8). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.
High [CVE-2026-91102] Multiple vulnerabilities could lead to remote code execution
Multiple vulnerabilities could lead to remote code execution. Red Hat rates this important (CVSS 7.8). Weakness: CWE-494. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.
High [CVE-2026-91098] Multiple vulnerabilities allow remote code execution and privilege escalation
Multiple vulnerabilities allow remote code execution and privilege escalation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-494. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.
High [CVE-2026-86003] Unauthorized DNS record modification via unvalidated DNS updates
Unauthorized DNS record modification via unvalidated DNS updates. Red Hat rates this important (CVSS 7.5). Weakness: CWE-306. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Connectivity Link 1; Red Hat OpenShift Container Platform 4.
High [CVE-2026-91097] Multiple vulnerabilities enable remote code execution and privilege escalation
Multiple vulnerabilities enable remote code execution and privilege escalation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.
High [CVE-2026-82399] Denial of Service due to unauthenticated memory exhaustion in custom transports
Denial of Service due to unauthenticated memory exhaustion in custom transports. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Connectivity Link 1; Red Hat OpenShift Container Platform 4.
High [CVE-2026-75516] RabbitMQ Java client: Denial of Service via oversized frames
RabbitMQ Java client: Denial of Service via oversized frames. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat Fuse 7.
High [CVE-2026-46352] Denial of Service via fragmented encapsulated traffic
Denial of Service via fragmented encapsulated traffic. Red Hat rates this important (CVSS 7.5). Weakness: CWE-833.