Red Hat Linux Security Advisories & CVEs
411 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Critical [CVE-2026-8524] Out of bounds write in WebAudio
Out of bounds write in WebAudio. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-8523] Use after free in Mojo
Use after free in Mojo. Red Hat rates this important (CVSS 9). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-8518] Use after free in Blink
Use after free in Blink. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-8517] Object lifecycle issue in WebShare
Object lifecycle issue in WebShare. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-8515] Use after free in HID
Use after free in HID. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-8514] Use after free in Aura
Use after free in Aura. Red Hat rates this critical (CVSS 9). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-8512] Use after free in FileSystem
Use after free in FileSystem. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-8511] Use after free in UI
Use after free in UI. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-8509] Heap buffer overflow in WebML
Heap buffer overflow in WebML. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-44484] Credential harvesting via introduced functionality
Credential harvesting via introduced functionality. Red Hat rates this important (CVSS 9.8). Weakness: CWE-829. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-44005] Sandbox Escape leading to Arbitrary Code Execution
Sandbox Escape leading to Arbitrary Code Execution. Red Hat rates this important (CVSS 9.8). Weakness: CWE-653. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.1.
Critical [CVE-2026-45411] Arbitrary Code Execution due to sandbox escape vulnerability
Arbitrary Code Execution due to sandbox escape vulnerability. Red Hat rates this important (CVSS 9.8). Weakness: CWE-237. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.1.
Critical [CVE-2026-44009] Arbitrary Code Execution via Sandbox Escape
Arbitrary Code Execution via Sandbox Escape. Red Hat rates this important (CVSS 9.8). Weakness: CWE-653. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.1.
Critical [CVE-2026-44008] Arbitrary code execution due to sandbox escape
Arbitrary code execution due to sandbox escape. Red Hat rates this important (CVSS 9.8). Weakness: CWE-1100. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.1.
Critical [CVE-2026-44007] Arbitrary code execution via nested NodeVM bypass
Arbitrary code execution via nested NodeVM bypass. Red Hat rates this important (CVSS 9.9). Weakness: CWE-1100. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.1.
Critical [CVE-2026-44006] Sandbox escape via arbitrary prototype access leading to arbitrary code execution
Sandbox escape via arbitrary prototype access leading to arbitrary code execution. Red Hat rates this important (CVSS 10). Weakness: CWE-914. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.1.
Critical [CVE-2026-43999] Remote code execution via NodeVM builtin allowlist bypass
Remote code execution via NodeVM builtin allowlist bypass. Red Hat rates this important (CVSS 9.9). Weakness: CWE-829. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.1.
Critical [CVE-2026-43997] Arbitrary code execution via sandbox escape
Arbitrary code execution via sandbox escape. Red Hat rates this important (CVSS 10). Weakness: CWE-653. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Ansible Automation Platform 2.1.
Critical [CVE-2026-7902] Out of bounds memory access in V8
Out of bounds memory access in V8. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-7908] Use after free in Fullscreen
Use after free in Fullscreen. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.