Red Hat Linux Security Advisories & CVEs
11870 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-61909] CalDAV/CardDAV multiget bypasses per-href ACL
CalDAV/CardDAV multiget bypasses per-href ACL. Red Hat rates this moderate (CVSS 5). Weakness: CWE-420. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: cyrus-imapd.
Medium [CVE-2026-61908] JMAP email-header blob ID out-of-bounds index
JMAP email-header blob ID out-of-bounds index. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: cyrus-imapd.
Medium [CVE-2026-88763] Unbounded recursion in AMQP field parser leads to denial of service
Unbounded recursion in AMQP field parser leads to denial of service. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-674. Affected product named by the advisory: Red Hat Service Interconnect 2.
Medium [CVE-2026-57822] Unsafe deserialization via JsonUtil CompositeData on management address
Unsafe deserialization via JsonUtil CompositeData on management address. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-502. Red Hat lists fixing advisory RHSA-2026:66488 with package artemis-core-client. Affected products named by the advisory: Red Hat AMQ Broker 7.13.6; Red Hat AMQ Broker 7.14.1; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; and 1 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform 8.
Medium [CVE-2026-49363] Pre-auth topology disclosure via CORE SUBSCRIBE_TOPOLOGY_V2 on channel0
Pre-auth topology disclosure via CORE SUBSCRIBE_TOPOLOGY_V2 on channel0. Red Hat rates this moderate (CVSS 5.3). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:66488 with package eap8-jackson-annotations-0:2.18.9-1.redhat_00003.1.el10eap, eap8-jbossws-cxf-0:7.4.0-1.Final_redhat_00001.1.el8eap, eap8-wildfly-0:8.1.8-9.GA_redhat_00006.1.el9eap, eap8-parsson-0:1.1.9-1.redhat_00001.1.el10eap. Affected products named by the advisory: Red Hat AMQ Broker 7.13.6; Red Hat AMQ Broker 7.14.1; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; and 1 more. Affected products named by the advisory: Red Hat JBoss Enterprise Application Platform Expansion Pack.
Medium [CVE-2026-93561] Memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling
Memcache binary codec signed/unsigned type mismatch causes frame desynchronization and response smuggling. Red Hat rates this important (CVSS 6.5). Weakness: CWE-1035. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7.
Medium [CVE-2026-93493] OCSP Validation Silently Skipped When a Response Omits the Optional nextUpdate Field
OCSP Validation Silently Skipped When a Response Omits the Optional nextUpdate Field. Red Hat rates this moderate (CVSS 5.9). Weakness: CWE-299. Affected product named by the advisory: Red Hat build of Apache Camel for Spring Boot 4.
Medium [CVE-2026-88264] /dev/console symlink follow allows root-owned file creation outside the rootfs
/dev/console symlink follow allows root-owned file creation outside the rootfs. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-59. Red Hat lists fixing advisory RHSA-2026:71668 with package crun-main-1.30-1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat OpenShift Container Platform 4.
Low [CVE-2026-88013] Information disclosure via HTTP backend forwarding headers on redirect
Information disclosure via HTTP backend forwarding headers on redirect. Red Hat rates this low (CVSS 3.7). Weakness: CWE-212. Affected products named by the advisory: Cryostat 4; Red Hat Advanced Cluster Management for Kubernetes 2.
Critical [CVE-2026-87528] Type confusion in Rust
Type confusion in Rust. Red Hat rates this important (CVSS 9.6). Weakness: CWE-843.
Critical [CVE-2026-87637] Use after free in Extensions
Use after free in Extensions. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825.
Critical [CVE-2026-87470] Improper quantity validation in Tint
Improper quantity validation in Tint. Red Hat rates this important (CVSS 9.6). Weakness: CWE-1284.
Critical [CVE-2026-87616] Improper initialization in Views
Improper initialization in Views. Red Hat rates this important (CVSS 9). Weakness: CWE-824.
Critical [CVE-2026-87648] Arbitrary code execution in Google Chrome due to use-after-free
Arbitrary code execution in Google Chrome due to use-after-free. Red Hat rates this important (CVSS 9). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Critical [CVE-2026-87500] ANGLE in Google Chrome: Arbitrary code execution via crafted HTML page
ANGLE in Google Chrome: Arbitrary code execution via crafted HTML page. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: webkitgtk4; and 1 more. Affected products named by the advisory: Red Hat package: webkit2gtk3.
Critical [CVE-2026-87654] Arbitrary code execution via buffer overflow in ANGLE
Arbitrary code execution via buffer overflow in ANGLE. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Critical [CVE-2026-87621] Google Chrome (ANGLE): Arbitrary Code Execution vulnerability
Google Chrome (ANGLE): Arbitrary Code Execution vulnerability. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Critical [CVE-2026-87604] ANGLE in Google Chrome: Arbitrary code execution via out-of-bounds read
ANGLE in Google Chrome: Arbitrary code execution via out-of-bounds read. Red Hat rates this important (CVSS 9). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Critical [CVE-2026-87512] Arbitrary code execution via use-after-free vulnerability in ANGLE
Arbitrary code execution via use-after-free vulnerability in ANGLE. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
High [CVE-2026-19816] PackageKit dnf5 ignores SIMULATE on RepoRemove
PackageKit dnf5 ignores SIMULATE on RepoRemove. Red Hat rates this important (CVSS 7.1). Weakness: CWE-863.