Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11617 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Low3.4Red Hat

Low [CVE-2026-92069] Spoofing issue in the DOM: Navigation component

Spoofing issue in the DOM: Navigation component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-601.

CVE-2026-92069
Unclassified
Sep 15, 2026
Low3.4Red Hat

Low [CVE-2026-92068] Site isolation issue in the Reader Mode component

Site isolation issue in the Reader Mode component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-653.

CVE-2026-92068
Unclassified
Sep 15, 2026
Low3.4Red Hat

Low [CVE-2026-92067] Use-after-free in the Widget: Gtk component

Use-after-free in the Widget: Gtk component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-364.

CVE-2026-92067
Unclassified
Sep 15, 2026
Low3.4Red Hat

Low [CVE-2026-92066] Sandbox escape in the Profile Backup component

Sandbox escape in the Profile Backup component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-653.

CVE-2026-92066
Unclassified
Sep 15, 2026
Low3.4Red Hat

Low [CVE-2026-92065] Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-787.

CVE-2026-92065
Unclassified
Sep 15, 2026
Low3.4Red Hat

Low [CVE-2026-92063] Denial-of-service in the Audio/Video component

Denial-of-service in the Audio/Video component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-770.

CVE-2026-92063
Unclassified
Sep 15, 2026
Low3.4Red Hat

Low [CVE-2026-92062] Privilege escalation in the Session Restore component

Privilege escalation in the Session Restore component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-266.

CVE-2026-92062
Unclassified
Sep 15, 2026
Low3.4Red Hat

Low [CVE-2026-92061] Incorrect boundary conditions in the Security: Process Sandboxing component

Incorrect boundary conditions in the Security: Process Sandboxing component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-403.

CVE-2026-92061
Unclassified
Sep 15, 2026
Low3.4Red Hat

Low [CVE-2026-92060] Use-after-free in the Internationalization component

Use-after-free in the Internationalization component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-825.

CVE-2026-92060
Unclassified
Sep 15, 2026
Low3.7Red Hat

Low [CVE-2026-91926] memory leak in ntlm_decode_target_info via duplicated AV_PAIR entries in NTLM CHALLENGE

memory leak in ntlm_decode_target_info via duplicated AV_PAIR entries in NTLM CHALLENGE. Red Hat rates this low (CVSS 3.7). Weakness: CWE-401. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat package: gssntlmssp.

CVE-2026-91926
Red Hat Enterprise Linux
Sep 15, 2026
High8.8Red Hat

High [CVE-2026-68489] Plesk Extensions Ruby and Node.js Toolkit: Arbitrary Code Execution via Static Code Injection

Plesk Extensions Ruby and Node.js Toolkit: Arbitrary Code Execution via Static Code Injection. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift Container Platform 4; Red Hat OpenShift Dev Spaces.

CVE-2026-68489
Unclassified
Sep 14, 2026
High7.4Red Hat

High [CVE-2026-53714] Information Disclosure via Unauthenticated xDS gRPC Server

Information Disclosure via Unauthenticated xDS gRPC Server. Red Hat rates this important (CVSS 7.4). Weakness: CWE-306.

CVE-2026-53714
Unclassified
Sep 14, 2026
High7.1Red Hat

High [CVE-2026-82049] Python tarfile module: File modification and content disclosure via crafted archives

Python tarfile module: File modification and content disclosure via crafted archives. Red Hat rates this important (CVSS 7.1). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:68135 with package python3-11-main-3.11.16-1.4.hum1, python3-12-main-3.12.14-1.3.hum1, python3-10-main-3.10.21-1.3.hum1, python3-13-main-3.13.15-1.3.hum1. Affected product named by the advisory: Red Hat Hardened Images.

CVE-2026-82049
Unclassified
Sep 14, 2026
High7.1Red Hat

High [CVE-2026-82035] Arbitrary file write via path traversal vulnerability

Arbitrary file write via path traversal vulnerability. Red Hat rates this important (CVSS 7.1). Weakness: CWE-22. Affected product named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3.

CVE-2026-82035
Unclassified
Sep 14, 2026
High7.5Red Hat

High [CVE-2026-53659] Denial of Service via unbounded gzip decompression

Denial of Service via unbounded gzip decompression. Red Hat rates this important (CVSS 7.5). Weakness: CWE-409.

CVE-2026-53659
Unclassified
Sep 14, 2026
High8.2Red Hat

High [CVE-2026-55451] Denial of Service via Prototype Pollution

Denial of Service via Prototype Pollution. Red Hat rates this important (CVSS 8.2). Weakness: CWE-915. Affected products named by the advisory: Red Hat OpenShift Container Platform 4; Red Hat Openshift Data Foundation 4.

CVE-2026-55451
Unclassified
Sep 14, 2026
High7.5Red Hat

High [CVE-2026-84445] Denial of Service via malformed RPC requests

Denial of Service via malformed RPC requests. Red Hat rates this important (CVSS 7.5). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:72884 with package rhoai/odh-kserve-agent-rhel9:1789570413, rhacm2/multicluster-role-assignment-rhel9:1790198006, cluster-observability-operator/prometheus-rhel9:1790857922, multicluster-engine/hypershift-addon-rhel9-operator:1790117675. Affected product named by the advisory: Red Hat Enterprise Linux 7.

CVE-2026-84445
Unclassified
Sep 14, 2026
High7.8Red Hat

High [CVE-2026-90947] out-of-bounds write in lighting effects plugin via crafted preset file

out-of-bounds write in lighting effects plugin via crafted preset file. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:75575 with package gimp-2:3.0.4-4.el9_8.14. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-90947
Unclassified
Sep 14, 2026
High7.8Red Hat

High [CVE-2026-90949] heap-based buffer overflow in PSP loader due to selection-channel geometry mismatch

heap-based buffer overflow in PSP loader due to selection-channel geometry mismatch. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8.

CVE-2026-90949
Unclassified
Sep 14, 2026
High7.8Red Hat

High [CVE-2026-90948] heap-based buffer overflow in ICO loader via integer overflow in embedded PNG dimensions

heap-based buffer overflow in ICO loader via integer overflow in embedded PNG dimensions. Red Hat rates this important (CVSS 7.8). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:75575 with package gimp-2:3.0.4-4.el9_8.14. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-90948
Unclassified
Sep 14, 2026

← All vendors