Red Hat Linux Security Advisories & CVEs
11898 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Medium [CVE-2026-86512] java-json-tools json-patch: Improper Access Control in Copy/Move Operations
java-json-tools json-patch: Improper Access Control in Copy/Move Operations. Red Hat rates this moderate (CVSS 6.3). Weakness: CWE-281. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat Build of Keycloak; Red Hat build of Quarkus; and 1 more. Affected products named by the advisory: Red Hat Fuse 7.
Low [CVE-2026-86564] Missing length validation before reading command_data in virtio-net control queue handler
Missing length validation before reading command_data in virtio-net control queue handler. Red Hat rates this low (CVSS 3.3). Weakness: CWE-125. Affected products named by the advisory: Fast Datapath for RHEL 10; Fast Datapath for RHEL 8; Fast Datapath for RHEL 9; Red Hat Enterprise Linux 10; and 4 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat package: dpdk.
Low [CVE-2026-87055] Base image referenced by mutable tag rather than sha256 digest
Base image referenced by mutable tag rather than sha256 digest. Red Hat rates this low (CVSS 2.6). Weakness: CWE-829.
Low [CVE-2026-87056] No automated dependency-update configuration for submodules or Containerfile
No automated dependency-update configuration for submodules or Containerfile. Red Hat rates this low (CVSS 2.6). Weakness: CWE-1104.
Low [CVE-2026-87051] resolveAndValidatePath performs lexical containment only — symlinks can escape the build context
resolveAndValidatePath performs lexical containment only — symlinks can escape the build context. Red Hat rates this low (CVSS 2.6). Weakness: CWE-59.
Low [CVE-2026-87052] No automated dependency-update or vulnerability-scanning configuration
No automated dependency-update or vulnerability-scanning configuration. Red Hat rates this low (CVSS 2.6). Weakness: CWE-1104.
Low [CVE-2026-87058] Hermetic build disabled by default; bundle build performs live network fetches
Hermetic build disabled by default; bundle build performs live network fetches. Red Hat rates this low (CVSS 2.6). Weakness: CWE-829.
Low [CVE-2026-87059] Unpinned pip dependency installation in bundle builder stage
Unpinned pip dependency installation in bundle builder stage. Red Hat rates this low (CVSS 2.6). Weakness: CWE-494.
Low [CVE-2026-87060] Renovate automerge enabled with base-image update exclusions
Renovate automerge enabled with base-image update exclusions. Red Hat rates this low (CVSS 2.6). Weakness: CWE-1357.
Low [CVE-2026-87061] bundle-hack/update_bundle.sh lacks fail-fast shell options
bundle-hack/update_bundle.sh lacks fail-fast shell options. Red Hat rates this low (CVSS 2.6). Weakness: CWE-252.
Low [CVE-2026-87063] tkn CLI installed from network without checksum or signature verification
tkn CLI installed from network without checksum or signature verification. Red Hat rates this low (CVSS 2.6). Weakness: CWE-494.
Low [CVE-2026-87064] GitHub workflows lack explicit least-privilege permissions blocks
GitHub workflows lack explicit least-privilege permissions blocks. Red Hat rates this low (CVSS 2.6). Weakness: CWE-269.
Low [CVE-2026-87065] Tekton task steps run as root without defense-in-depth securityContext hardening
Tekton task steps run as root without defense-in-depth securityContext hardening. Red Hat rates this low (CVSS 2.6). Weakness: CWE-250.
Critical [CVE-2026-18922] SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property
SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-287. Red Hat lists fixing advisory RHSA-2026:64783 with package 389-ds-base-0:2.4.5-29.el9_4, 389-ds-base-0:2.6.1-24.el9_6, 389-ds-base-0:3.0.6-21.el10_0, redhat-ds:12-9020020260903155914.1674d574. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Affected products named by the advisory: Red Hat Directory Server 11.5 E4S for RHEL 8; Red Hat Directory Server 11.7 E4S for RHEL 8; Red Hat Directory Server 11.9 for RHEL 8; Red Hat Directory Server 12.2 E4S for RHEL 9; and 13 more.
Critical [CVE-2026-76578] unauthenticated LDAP client can obtain administrator credentials via the self-managed-token ACI
unauthenticated LDAP client can obtain administrator credentials via the self-managed-token ACI. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:72279 with package ipa-0:4.13.4-1.el9_8, ipa-0:4.13.4-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-6377] Information disclosure via path traversal vulnerability
Information disclosure via path traversal vulnerability. Red Hat rates this important (CVSS 7.5). Weakness: CWE-22.
High [CVE-2026-19843] Command injection via unescaped LDAP DN in Cockpit 389 Console LDAP editor
Command injection via unescaped LDAP DN in Cockpit 389 Console LDAP editor. Red Hat rates this important (CVSS 8.4). Weakness: CWE-78. Red Hat lists fixing advisory RHSA-2026:64780 with package 389-ds-base-0:3.0.6-4.el10dsrv, redhat-ds:12-9040020260903102623.1674d574, redhat-ds:12-9020020260903155914.1674d574, 389-ds-base-0:3.2.0-7.el10dsrv. Affected products named by the advisory: Red Hat Directory Server 11.7 E4S for RHEL 8; Red Hat Directory Server 11.9 for RHEL 8; Red Hat Directory Server 12.2 E4S for RHEL 9; Red Hat Directory Server 12.4 E4S for RHEL 9; and 9 more. Affected products named by the advisory: Red Hat Directory Server 11.5 E4S for RHEL 8; Red Hat Directory Server 12.6 EUS for RHEL 9; Red Hat Directory Server 12.8 for RHEL 9; Red Hat Directory Server 13.0 EUS for RHEL 10; and 4 more.
High [CVE-2026-18453] pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search
pre-authentication NULL pointer dereference via paged results and USE_ONE_BACKEND control in op_shared_search. Red Hat rates this important (CVSS 7.5). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:64783 with package 389-ds-base-0:2.4.5-29.el9_4, 389-ds-base-0:2.6.1-24.el9_6, 389-ds-base-0:3.0.6-21.el10_0, redhat-ds:12-9020020260903155914.1674d574. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7. Affected products named by the advisory: Red Hat Directory Server 11.5 E4S for RHEL 8; Red Hat Directory Server 11.7 E4S for RHEL 8; Red Hat Directory Server 11.9 for RHEL 8; Red Hat Directory Server 12.2 E4S for RHEL 9; and 13 more.
High [CVE-2026-11774 +1] heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet
heap buffer overflow via SASL wrapped-record length lower-bound underflow in sasl_io_start_packet(). Red Hat rates this important (CVSS 7.5). Weakness: CWE-191. Red Hat lists fixing advisory RHSA-2026:64783 with package 389-ds-base-0:2.4.5-29.el9_4, 389-ds-base-0:2.6.1-24.el9_6, 389-ds-base-0:3.0.6-21.el10_0, redhat-ds:12-9020020260903155914.1674d574. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7. Affected products named by the advisory: Red Hat Directory Server 11.5 E4S for RHEL 8; Red Hat Directory Server 11.7 E4S for RHEL 8; Red Hat Directory Server 11.9 for RHEL 8; Red Hat Directory Server 12.2 E4S for RHEL 9; and 13 more.
High [CVE-2026-76560] anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN
anonymous LDAP client can defeat SELFDN ACI bind-rule checks via empty bind DN. Red Hat rates this important (CVSS 7.5). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:64783 with package 389-ds-base-0:2.4.5-29.el9_4, 389-ds-base-0:2.6.1-24.el9_6, 389-ds-base-0:3.0.6-21.el10_0, redhat-ds:12-9020020260903155914.1674d574. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7. Affected products named by the advisory: Red Hat Directory Server 11.5 E4S for RHEL 8; Red Hat Directory Server 11.7 E4S for RHEL 8; Red Hat Directory Server 11.9 for RHEL 8; Red Hat Directory Server 12.2 E4S for RHEL 9; and 13 more.