Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

5208 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Linux release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Linux advisories

Medium6.1Linux

Medium [CVE-2026-8974] Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151

Memory safety bugs fixed in Firefox ESR 140.11 and Firefox 151. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-787. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-8974
Unclassified
May 19, 2026
Medium6.1Linux

Medium [CVE-2026-8959] Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-653. Affected package(s): thunderbird. Resolved in Red Hat advisory RHSA-2026:21381 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.

CVE-2026-8959
Unclassified
May 19, 2026
Medium6.1Linux

Medium [CVE-2026-8958] Information disclosure, sandbox escape in the Security: Process Sandboxing component

Information disclosure, sandbox escape in the Security: Process Sandboxing component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-403. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-8958
Unclassified
May 19, 2026
Medium6.1Linux

Medium [CVE-2026-8957] Privilege escalation in the Enterprise Policies component

Privilege escalation in the Enterprise Policies component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-266. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-8957
Unclassified
May 19, 2026
Medium6.1Linux

Medium [CVE-2026-8956] Integer overflow in the Networking: JAR component

Integer overflow in the Networking: JAR component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-190. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-8956
Unclassified
May 19, 2026
Medium6.1Linux

Medium [CVE-2026-8955] Privilege escalation in the DOM: Workers component

Privilege escalation in the DOM: Workers component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-266. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-8955
Unclassified
May 19, 2026
Medium6.1Linux

Medium [CVE-2026-8954] Incorrect boundary conditions, integer overflow in the Audio/Video component

Incorrect boundary conditions, integer overflow in the Audio/Video component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-190. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-8954
Unclassified
May 19, 2026
Medium6.1Linux

Medium [CVE-2026-8953] Sandbox escape due to use-after-free in the Disability Access APIs component

Sandbox escape due to use-after-free in the Disability Access APIs component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-8953
Unclassified
May 19, 2026
Medium6.1Linux

Medium [CVE-2026-8950] Same-origin policy bypass in the Networking: HTTP component

Same-origin policy bypass in the Networking: HTTP component. Red Hat rates this moderate (CVSS 6.1). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-8950
Unclassified
May 19, 2026
Medium4.9Linux

Medium [CVE-2026-37978] Information Disclosure via evaluate-scopes Admin API

Information Disclosure via evaluate-scopes Admin API. Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-639. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.12, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:19596 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-37978
Unclassified
May 19, 2026
Medium4.3Linux

Medium [CVE-2026-37981] Information disclosure via broken access control in user lookup endpoint

Information disclosure via broken access control in user lookup endpoint. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-1220. Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.12, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:19596 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-37981
Unclassified
May 19, 2026
Medium5.4Linux

Medium [CVE-2026-8922] Security flaw in org.keycloak/keycloak-services

Security flaw in org.keycloak/keycloak-services. Red Hat rates this moderate (CVSS 5.4). Weakness: CWE-303. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9-operator, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8922
Unclassified
May 19, 2026
Medium4.3Linux

Medium [CVE-2026-8830] Policy bypass during WebAuthn credential registration via client-side JavaScript manipulation

Policy bypass during WebAuthn credential registration via client-side JavaScript manipulation. Red Hat rates this moderate (CVSS 4.3). Weakness: CWE-603. Affected package(s): rhbk/keycloak-operator-bundle:26.4.13, rhbk/keycloak-rhel9-operator:26.4, rhbk/keycloak-rhel9-operator, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-operator-bundle:26.6.3, rhbk/keycloak-rhel9:26.6. Resolved in Red Hat advisory RHSA-2026:30049 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-8830
Unclassified
May 19, 2026
Medium6.5Linux

Medium [CVE-2026-37979] Information disclosure via OIDC token introspection endpoint audience bypass

Information disclosure via OIDC token introspection endpoint audience bypass. Red Hat rates this moderate (CVSS 6.5). Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.12, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:19596 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-37979
Unclassified
May 19, 2026
Medium6.8Linux

Medium [CVE-2026-37982] Unauthorized account takeover via WebAuthn token replay

Unauthorized account takeover via WebAuthn token replay. Red Hat rates this moderate (CVSS 6.8). Affected package(s): rhbk/keycloak-rhel9, rhbk/keycloak-operator-bundle:26.4.12, rhbk/keycloak-rhel9:26.4, rhbk/keycloak-rhel9-operator:26.4. Resolved in Red Hat advisory RHSA-2026:19596 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux.

CVE-2026-37982
Unclassified
May 19, 2026
Medium6.5Vendor: HighLinux

Medium [CVE-2026-9113] Out of bounds read in GPU

Out of bounds read in GPU. Red Hat rates this important (CVSS 6.5). Weakness: CWE-125. No fix erratum has been published yet; monitor the Red Hat CVE page and apply the RHSA when released. Affected product named by the advisory: Red Hat Enterprise Linux.

CVE-2026-9113
Unclassified
May 19, 2026
Low3.4Linux

Low [CVE-2026-8970] Privilege escalation in the Security component

Privilege escalation in the Security component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-266. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-8970
Unclassified
May 19, 2026
Low3.4Linux

Low [CVE-2026-8968] Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component

Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. Red Hat rates this low (CVSS 3.4). Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-8968
Unclassified
May 19, 2026
Low3.4Linux

Low [CVE-2026-8962] Mitigation bypass in the DOM: Security component

Mitigation bypass in the DOM: Security component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-358. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-8962
Unclassified
May 19, 2026
Low3.4Linux

Low [CVE-2026-8961] Spoofing issue in the Form Autofill component

Spoofing issue in the Form Autofill component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-472. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:26551 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.

CVE-2026-8961
Unclassified
May 19, 2026

← All vendors