Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

11870 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Medium5.4Red Hat

Medium [CVE-2026-87501] UI misrepresentation in Passwords

UI misrepresentation in Passwords. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-1021.

CVE-2026-87501
Unclassified
Sep 9, 2026
Medium5.4Red Hat

Medium [CVE-2026-87475] Missing authorization in Omnibox

Missing authorization in Omnibox. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-551.

CVE-2026-87475
Unclassified
Sep 9, 2026
Medium6.5Red Hat

Medium [CVE-2026-87476] Incorrect authorization in Loader

Incorrect authorization in Loader. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-551.

CVE-2026-87476
Unclassified
Sep 9, 2026
Medium4.3Red Hat

Medium [CVE-2026-87497] Uninitialized resource in Codecs

Uninitialized resource in Codecs. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-824.

CVE-2026-87497
Unclassified
Sep 9, 2026
Medium5.4Red Hat

Medium [CVE-2026-87645] Improper state validation in Safebrowsing

Improper state validation in Safebrowsing. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-79.

CVE-2026-87645
Unclassified
Sep 9, 2026
Medium6.5Red Hat

Medium [CVE-2026-87443] Missing authorization in Actor

Missing authorization in Actor. Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-425.

CVE-2026-87443
Unclassified
Sep 9, 2026
Medium4.6Red Hat

Medium [CVE-2026-87465] Incorrect authorization in Downloads

Incorrect authorization in Downloads. Red Hat rates this moderate (CVSS 4.6). Weakness: CWE-1021.

CVE-2026-87465
Unclassified
Sep 9, 2026
Medium5.7Red Hat

Medium [CVE-2026-87657] Use after free in V8

Use after free in V8. Red Hat rates this moderate (CVSS 5.7). Weakness: CWE-825.

CVE-2026-87657
Unclassified
Sep 9, 2026
Medium4.3Red Hat

Medium [CVE-2026-87875] Heap out-of-bounds read in cupsUTF32ToUTF8 via missing source-length bound

Heap out-of-bounds read in cupsUTF32ToUTF8() via missing source-length bound. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:66600 with package cups-main-2.4.19-4.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: cups.

CVE-2026-87875
Red Hat Enterprise Linux
Sep 9, 2026
Medium5.6Red Hat

Medium [CVE-2026-88265] /dev/null symlink follow during stdio reopen allows host bind-mount write and chown

/dev/null symlink follow during stdio reopen allows host bind-mount write and chown. Red Hat rates this moderate (CVSS 5.6). Weakness: CWE-59. Affected product named by the advisory: Red Hat Hardened Images. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.

CVE-2026-88265
Unclassified
Sep 9, 2026
Medium5.5Red Hat

Medium [CVE-2026-80919] fix recursive ww_mutex acquire in amdgpu_devcoredump_format

fix recursive ww_mutex acquire in amdgpu_devcoredump_format. Red Hat rates this moderate (CVSS 5.5). Weakness: CWE-833. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat package: kernel.

CVE-2026-80919
Linux Kernel
Sep 9, 2026
Low3.0Red Hat

Low [CVE-2026-27447 +1] Remaining case-insensitive username matching in scheduler side paths (CVE-2026-27447 follow-up)

Remaining case-insensitive username matching in scheduler side paths (CVE-2026-27447 follow-up). Red Hat rates this low (CVSS 3). Weakness: CWE-178. Red Hat lists fixing advisory RHSA-2026:67568 with package cups-main-2.4.19-4.2.hum1. Affected products named by the advisory: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; and 3 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4.

CVE-2026-27447CVE-2026-87876
Unclassified
Sep 9, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-78234] Service-CA signing oracle allows arbitrary-CN certificate issuance to namespace edit users

Service-CA signing oracle allows arbitrary-CN certificate issuance to namespace edit users. Red Hat rates this important (CVSS 9.9). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:66120 with package rhbac-4/hawtio-operator-bundle:2.0.1-8, rhbac-4/hawtio-rhel9-operator:2.0.1-10. Affected product named by the advisory: Red Hat build of Apache Camel - HawtIO 4.

CVE-2026-78234
Unclassified
Sep 8, 2026
High8.2Red Hat

High [CVE-2026-53938] Heap buffer overflow in AES Key Wrap decryption leads to denial of service

Heap buffer overflow in AES Key Wrap decryption leads to denial of service. Red Hat rates this important (CVSS 8.2). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:73017 with package cjose-0:0.6.1-13.el9_2.1, cjose-0:0.6.1-16.el9_4.1. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-53938
Unclassified
Sep 8, 2026
High8.7Red Hat

High [CVE-2026-87049] Over-permissive GITHUB_TOKEN and GCP WIF secrets granted to third-party reusable workflow on untrusted-triggerable events

Over-permissive GITHUB_TOKEN and GCP WIF secrets granted to third-party reusable workflow on untrusted-triggerable events. Red Hat rates this important (CVSS 8.7). Weakness: CWE-269.

CVE-2026-87049
Unclassified
Sep 8, 2026
High8.0Red Hat

High [CVE-2026-79721] Arbitrary code execution via maliciously crafted model artifact

Arbitrary code execution via maliciously crafted model artifact. Red Hat rates this important (CVSS 8). Weakness: CWE-502. Affected product named by the advisory: Red Hat OpenShift AI (RHOAI).

CVE-2026-79721
Unclassified
Sep 8, 2026
High7.5Red Hat

High [CVE-2026-57099] Denial of Service via uncontrolled resource allocation

Denial of Service via uncontrolled resource allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770.

CVE-2026-57099
Unclassified
Sep 8, 2026
High7.0Red Hat

High [CVE-2026-69806] .NET Elevation of Privilege Vulnerability

.NET Elevation of Privilege Vulnerability. Red Hat rates this important (CVSS 7). Weakness: CWE-200. Red Hat lists fixing advisory RHSA-2026:66863 with package dotnet9.0-0:9.0.121-1.el9_8, dotnet10.0-0:10.0.112-1.el9_8, dotnet9.0-0:9.0.121-1.el8_10, dotnet10.0-0:10.0.112-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-69806
Unclassified
Sep 8, 2026
High7.5Red Hat

High [CVE-2026-12611] org.eclipse.jetty.http2/jetty-http2-common: Jetty: Denial of Service via HTTP/2 race condition

org.eclipse.jetty.http2/jetty-http2-common: Jetty: Denial of Service via HTTP/2 race condition. Red Hat rates this important (CVSS 7.5). Weakness: CWE-367. Affected products named by the advisory: OpenShift Developer Tools and Services; Red Hat Offline Knowledge Portal.

CVE-2026-12611
Unclassified
Sep 8, 2026
High8.2Red Hat

High [CVE-2026-19203] HTTP request smuggling via crafted chunked requests

HTTP request smuggling via crafted chunked requests. Red Hat rates this important (CVSS 8.2). Weakness: CWE-444. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat AMQ Broker 7; Red Hat build of Apache Camel 4 for Quarkus 3; and 11 more. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apache Camel - HawtIO 4; Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; and 7 more.

CVE-2026-19203
Red Hat Enterprise Linux
Sep 8, 2026

← All vendors