Red Hat Linux Security Advisories & CVEs
413 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Critical [CVE-2026-7342] Use after free in WebView
Use after free in WebView. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-7333] Use after free in GPU
Use after free in GPU. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-7361] Use after free in iOS
Use after free in iOS. Red Hat rates this important (CVSS 9.6). No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-42208] Unauthorized data access and modification via SQL injection
Unauthorized data access and modification via SQL injection. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-89. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-40976] Security bypass due to ineffective default web security
Security bypass due to ineffective default web security. Red Hat rates this important (CVSS 9.1). Weakness: CWE-305. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Data Grid 8.
Critical [CVE-2026-33454] Altered application behavior via header injection
Altered application behavior via header injection. Red Hat rates this critical (CVSS 9.4). Weakness: CWE-1173. Affected package(s): camel-mail. Resolved in Red Hat advisory RHSA-2026:19835 — update the affected packages (`sudo dnf update`). Affected product named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3.
Critical [CVE-2026-41635] Arbitrary code execution via classname allowlist bypass
Arbitrary code execution via classname allowlist bypass. Red Hat rates this low (CVSS 9.8). Weakness: CWE-502. Affected package(s): mina-core. Resolved in Red Hat advisory RHSA-2026:17668 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-40453] Remote Code Execution and Arbitrary File Write via case-variant header injection
Remote Code Execution and Arbitrary File Write via case-variant header injection. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-178. Affected package(s): camel-http-starter, camel-google-pubsub, camel-http-common, camel-jms, camel-http-base, camel-http. Resolved in Red Hat advisory RHSA-2026:19835 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Build of Apache Camel 4.14 for Quarkus 3.27; Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14; Red Hat build of Apache Camel 4 for Quarkus 3.
Critical [CVE-2026-6921] Race in GPU
Race in GPU. Red Hat rates this important (CVSS 9.6). Weakness: CWE-368. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-6920] Out of bounds read in GPU
Out of bounds read in GPU. Red Hat rates this important (CVSS 9). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-41179] Unauthenticated local command execution via exposed RC endpoint
Unauthenticated local command execution via exposed RC endpoint. Red Hat rates this important (CVSS 9.8). Weakness: CWE-94. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-41176] Unauthorized access to administrative functions through unauthenticated Remote Control endpoint.
Unauthorized access to administrative functions through unauthenticated Remote Control endpoint.. Red Hat rates this important (CVSS 9.8). Weakness: CWE-15. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-40372] Privilege escalation via improper cryptographic signature verification
Privilege escalation via improper cryptographic signature verification. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-347. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-41245] Arbitrary file write via path traversal when extracting crafted RAR archives.
Arbitrary file write via path traversal when extracting crafted RAR archives.. Red Hat rates this important (CVSS 9.3). Weakness: CWE-22. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected products named by the advisory: Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform Expansion Pack.
Critical [CVE-2026-6388] Cross-Namespace Privilege Escalation via insufficient namespace validation
Cross-Namespace Privilege Escalation via insufficient namespace validation. Red Hat rates this important (CVSS 9.1). Weakness: CWE-1220. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat OpenShift GitOps.
Critical [CVE-2026-6308] Out of bounds read in Media
Out of bounds read in Media. Red Hat rates this important (CVSS 9.6). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-6306] Heap buffer overflow in PDFium
Heap buffer overflow in PDFium. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-6299] Use after free in Prerender
Use after free in Prerender. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-6311] Uninitialized Use in Accessibility
Uninitialized Use in Accessibility. Red Hat rates this important (CVSS 9). Weakness: CWE-824. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.
Critical [CVE-2026-6296] Heap buffer overflow in ANGLE
Heap buffer overflow in ANGLE. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-131. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.