Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11553 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.5Vendor: LowRed Hat Updated

Medium [CVE-2026-90202] Avoid freeing unallocated PCIe SGL buffers

Avoid freeing unallocated PCIe SGL buffers. Red Hat rates this low (CVSS 5.5). Weakness: CWE-476. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: kernel-rt.

CVE-2026-90202
Linux Kernel
Sep 17, 2026
Low3.0Red Hat

Low [CVE-2026-93378] Missing authorization in Storage

Missing authorization in Storage. Red Hat rates this low (CVSS 3). Weakness: CWE-653.

CVE-2026-93378
Unclassified
Sep 17, 2026
Low3.7Red Hat

Low [CVE-2026-85716] Server impersonation due to unverified authentication responses

Server impersonation due to unverified authentication responses. Red Hat rates this low (CVSS 3.7). Weakness: CWE-347. Affected product named by the advisory: Red Hat Fuse 7.

CVE-2026-85716
Unclassified
Sep 17, 2026
Low2.5Red Hat

Low [CVE-2026-92962] Information disclosure via stack trace interception

Information disclosure via stack trace interception. Red Hat rates this low (CVSS 2.5). Weakness: CWE-915.

CVE-2026-92962
Unclassified
Sep 17, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-92828] Operator ServiceAccount bound to cluster-admin

Operator ServiceAccount bound to cluster-admin. Red Hat rates this important (CVSS 9). Weakness: CWE-250. Affected product named by the advisory: Red Hat OpenShift Container Platform 4.

CVE-2026-92828
Unclassified
Sep 16, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-59969] Improper certificate validation in FIPS mode allows quorum compromise

Improper certificate validation in FIPS mode allows quorum compromise. Red Hat rates this important (CVSS 9). Weakness: CWE-295. Affected products named by the advisory: Red Hat AMQ Broker 7; Red Hat build of Apache Camel for Spring Boot 4; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack; and 2 more. Affected products named by the advisory: Red Hat Offline Knowledge Portal; Red Hat OpenShift AI (RHOAI).

CVE-2026-59969
Unclassified
Sep 16, 2026
Critical9.8Red Hat

Critical [CVE-2026-81642] Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY

Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-122. Red Hat lists fixing advisory RHSA-2026:71419 with package unbound-0:1.6.6-5.el7_9.2, unbound-0:1.16.2-3.el9_2.6, unbound-0:1.16.2-8.el9_4.3, unbound-0:1.16.2-19.el9_6.2. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8.

CVE-2026-81642
Unclassified
Sep 16, 2026
High7.5Red Hat

High [CVE-2026-92599] Denial of Service via `isoDate` validation regular expression

Denial of Service via `isoDate` validation regular expression. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1333. Red Hat lists fixing advisory RHSA-2026:68778 with package grafana13-2-main-13.2.1-0.5.hum1, grafana13-1-main-13.1.6-0.2.hum1, grafana12-4-main-12.4.10-0.6.hum1. Affected products named by the advisory: Red Hat Hardened Images; Gatekeeper 3; Migration Toolkit for Containers; Red Hat Data Grid 8; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; and 1 more.

CVE-2026-92599
Red Hat Enterprise Linux
Sep 16, 2026
High7.5Red Hat

High [CVE-2026-92596] Denial of Service in addressparser component

Denial of Service in addressparser component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Affected product named by the advisory: Self-service automation portal 2.

CVE-2026-92596
Unclassified
Sep 16, 2026
High8.0Red Hat

High [CVE-2026-85469] Release workflow uses third-party Action pinned to mutable @master with registry credentials in scope

Release workflow uses third-party Action pinned to mutable @master with registry credentials in scope. Red Hat rates this important (CVSS 8). Weakness: CWE-1357. Affected product named by the advisory: Red Hat Quay 3.

CVE-2026-85469
Unclassified
Sep 16, 2026
High7.8Red Hat

High [CVE-2026-92786] Out-of-bounds write via crafted model file

Out-of-bounds write via crafted model file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-92786
Unclassified
Sep 16, 2026
High8.4Red Hat

High [CVE-2026-91106] heap-based buffer overflow can lead to remote code execution

heap-based buffer overflow can lead to remote code execution. Red Hat rates this important (CVSS 8.4). Weakness: CWE-122. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.

CVE-2026-91106
Red Hat Enterprise Linux
Sep 16, 2026
High8.8Red Hat

High [CVE-2026-91105] Remote code execution and privilege escalation vulnerabilities

Remote code execution and privilege escalation vulnerabilities. Red Hat rates this important (CVSS 8.8). Weakness: CWE-266. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.

CVE-2026-91105
Red Hat Enterprise Linux
Sep 16, 2026
High7.8Red Hat

High [CVE-2026-91102] Multiple vulnerabilities could lead to remote code execution

Multiple vulnerabilities could lead to remote code execution. Red Hat rates this important (CVSS 7.8). Weakness: CWE-494. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.

CVE-2026-91102
Red Hat Enterprise Linux
Sep 16, 2026
High8.8Red Hat

High [CVE-2026-91098] Multiple vulnerabilities allow remote code execution and privilege escalation

Multiple vulnerabilities allow remote code execution and privilege escalation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-494. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.

CVE-2026-91098
Red Hat Enterprise Linux
Sep 16, 2026
High7.5Red Hat

High [CVE-2026-86003] Unauthorized DNS record modification via unvalidated DNS updates

Unauthorized DNS record modification via unvalidated DNS updates. Red Hat rates this important (CVSS 7.5). Weakness: CWE-306. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Connectivity Link 1; Red Hat OpenShift Container Platform 4.

CVE-2026-86003
Unclassified
Sep 16, 2026
High8.8Red Hat

High [CVE-2026-91097] Multiple vulnerabilities enable remote code execution and privilege escalation

Multiple vulnerabilities enable remote code execution and privilege escalation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.

CVE-2026-91097
Red Hat Enterprise Linux
Sep 16, 2026
High7.5Red Hat

High [CVE-2026-82399] Denial of Service due to unauthenticated memory exhaustion in custom transports

Denial of Service due to unauthenticated memory exhaustion in custom transports. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Connectivity Link 1; Red Hat OpenShift Container Platform 4.

CVE-2026-82399
Unclassified
Sep 16, 2026
High7.5Red Hat

High [CVE-2026-75516] RabbitMQ Java client: Denial of Service via oversized frames

RabbitMQ Java client: Denial of Service via oversized frames. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat Fuse 7.

CVE-2026-75516
Unclassified
Sep 16, 2026
High7.5Red Hat

High [CVE-2026-46352] Denial of Service via fragmented encapsulated traffic

Denial of Service via fragmented encapsulated traffic. Red Hat rates this important (CVSS 7.5). Weakness: CWE-833.

CVE-2026-46352
Unclassified
Sep 16, 2026

← All vendors