Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5276 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Medium5.7Vendor: HighLinux

Medium [CVE-2026-11669] Integer overflow in Media

Integer overflow in Media. Red Hat rates this important (CVSS 5.7). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11669
Unclassified
Jun 8, 2026
Medium6.8Vendor: HighLinux

Medium [CVE-2026-11686] Insufficient validation of untrusted input in Dawn

Insufficient validation of untrusted input in Dawn. Red Hat rates this important (CVSS 6.8). Weakness: CWE-346. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11686
Unclassified
Jun 8, 2026
Medium6.8Vendor: HighLinux

Medium [CVE-2026-11675] Insufficient validation of untrusted input in Skia

Insufficient validation of untrusted input in Skia. Red Hat rates this important (CVSS 6.8). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11675
Unclassified
Jun 8, 2026
Medium6.8Vendor: HighLinux

Medium [CVE-2026-11691] Insufficient validation of untrusted input in New Tab Page

Insufficient validation of untrusted input in New Tab Page. Red Hat rates this important (CVSS 6.8). Weakness: CWE-346. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11691
Unclassified
Jun 8, 2026
Medium5.7Vendor: HighLinux

Medium [CVE-2026-11684] Insufficient policy enforcement in Network

Insufficient policy enforcement in Network. Red Hat rates this important (CVSS 5.7). Weakness: CWE-940. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11684
Unclassified
Jun 8, 2026
Medium6.8Vendor: HighLinux

Medium [CVE-2026-11658] Insufficient validation of untrusted input in Extensions

Insufficient validation of untrusted input in Extensions. Red Hat rates this important (CVSS 6.8). Weakness: CWE-1286. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11658
Unclassified
Jun 8, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-11668] Uninitialized Use in Codecs

Uninitialized Use in Codecs. Red Hat rates this important (CVSS 6.5). Weakness: CWE-824. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11668
Unclassified
Jun 8, 2026
Critical9.1Vendor: HighLinux

Critical [CVE-2026-53469] Unprotected DELETE Endpoint Wipes All Tenant Data

Unprotected DELETE Endpoint Wipes All Tenant Data. Red Hat rates this important (CVSS 9.1). Weakness: CWE-306. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-53469
Unclassified
Jun 7, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-53470] GetSourceDownloadURL Missing Organization Check

GetSourceDownloadURL Missing Organization Check. Red Hat rates this important (CVSS 9.6). Weakness: CWE-639. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-53470
Unclassified
Jun 7, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-53471] Agent API Ignores JWT source_id Claim

Agent API Ignores JWT source_id Claim. Red Hat rates this important (CVSS 9.6). Weakness: CWE-639. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-53471
Unclassified
Jun 7, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-53474] Second-Order SQL Injection via RVTools Upload

Second-Order SQL Injection via RVTools Upload. Red Hat rates this important (CVSS 9.6). Weakness: CWE-89. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-53474
Unclassified
Jun 7, 2026
Critical9.3Vendor: HighLinux

Critical [CVE-2026-53475] TLS Verification Disabled on All vCenter Connections

TLS Verification Disabled on All vCenter Connections. Red Hat rates this important (CVSS 9.3). Weakness: CWE-295. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-53475
Unclassified
Jun 7, 2026
Critical9.6Vendor: HighLinux

Critical [CVE-2026-53476] VDDK Tarball Chained-Symlink Arbitrary File Write

VDDK Tarball Chained-Symlink Arbitrary File Write. Red Hat rates this important (CVSS 9.6). Weakness: CWE-59. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-53476
Unclassified
Jun 7, 2026
High7.3Linux

High [CVE-2026-11463] Type confusion vulnerability in Shared Pointer Handler

Type confusion vulnerability in Shared Pointer Handler. Red Hat rates this important (CVSS 7.3). Weakness: CWE-843. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-11463
Unclassified
Jun 7, 2026
High7.3Linux

High [CVE-2026-53473] Stored XSS via javascript: URL in Agent Credential Link

Stored XSS via javascript: URL in Agent Credential Link. Red Hat rates this important (CVSS 7.3). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-53473
Unclassified
Jun 7, 2026
Medium6.3Vendor: HighLinux

Medium [CVE-2026-53472] credentialUrl Validator Accepts javascript: URLs

credentialUrl Validator Accepts javascript: URLs. Red Hat rates this important (CVSS 6.3). Weakness: CWE-79. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-53472
Unclassified
Jun 7, 2026
High7.8Linux

High [CVE-2026-11332] argument injection in ansible-galaxy role install leads to arbitrary code execution

argument injection in ansible-galaxy role install leads to arbitrary code execution. Red Hat rates this important (CVSS 7.8). Weakness: CWE-88. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Discovery 2; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; and 11 more.

CVE-2026-11332
Red Hat Enterprise Linux
Jun 5, 2026
High7.5Linux

High [CVE-2026-10732] Arbitrary file write leading to remote code execution via crafted ZIP archive (Zip Slip)

Arbitrary file write leading to remote code execution via crafted ZIP archive (Zip Slip). Red Hat rates this important (CVSS 7.5). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Build of Keycloak; Red Hat Hardened Images.

CVE-2026-10732
Unclassified
Jun 5, 2026
High7.5Linux

High [CVE-2026-41567] Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload

Moby/Docker Engine: Arbitrary Code Execution via malicious container image and compressed archive upload. Red Hat rates this important (CVSS 7.5). Weakness: CWE-427. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Openshift Data Foundation 4.22; OpenShift Lightspeed; OpenShift Source-to-Image (S2I); Red Hat Advanced Cluster Management for Kubernetes 2; and 14 more.

CVE-2026-41567
Red Hat Enterprise Linux
Jun 5, 2026
Low2.7Linux

Low [CVE-2026-9088] Information disclosure due to user profile permission bypass

Information disclosure due to user profile permission bypass. Red Hat rates this low (CVSS 2.7). Weakness: CWE-1220. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9088
Unclassified
Jun 5, 2026

← All vendors