Red Hat Linux Security Advisories & CVEs
5204 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
Medium [CVE-2026-6770] Other issue in the Storage: IndexedDB component
Other issue in the Storage: IndexedDB component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-440. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:10757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2026-6771] Mitigation bypass in the DOM: Security component
Mitigation bypass in the DOM: Security component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-358. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:10757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2026-6769] Privilege escalation in the Debugger component
Privilege escalation in the Debugger component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-266. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:10757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2026-6767] Other issue in the Libraries component in NSS
Other issue in the Libraries component in NSS. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-676. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:10757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2026-6766] Incorrect boundary conditions in the Libraries component in NSS
Incorrect boundary conditions in the Libraries component in NSS. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-125. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:10757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2026-6764] Incorrect boundary conditions in the DOM: Device Interfaces component
Incorrect boundary conditions in the DOM: Device Interfaces component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-805. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:10757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2026-6765] Information disclosure in the Form Autofill component
Information disclosure in the Form Autofill component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-359. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:10757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2026-6763] Mitigation bypass in the File Handling component
Mitigation bypass in the File Handling component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-66. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:10757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2026-6762] Spoofing issue in the DOM: Core & HTML component
Spoofing issue in the DOM: Core & HTML component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-1021. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:10757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2026-6761] Privilege escalation in the Networking component
Privilege escalation in the Networking component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-266. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:10757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2026-6759] Use-after-free in the Widget: Cocoa component
Use-after-free in the Widget: Cocoa component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-825. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:10757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2026-6757] Invalid pointer in the JavaScript: WebAssembly component
Invalid pointer in the JavaScript: WebAssembly component. Red Hat rates this moderate (CVSS 6.1). Weakness: CWE-823. Affected package(s): thunderbird, firefox. Resolved in Red Hat advisory RHSA-2026:10757 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7.
Medium [CVE-2026-22004] InnoDB unspecified vulnerability (CPU Apr 2026)
InnoDB unspecified vulnerability (CPU Apr 2026). Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-770. Affected package(s): mysql:8.4, mysql, mysql8.4, mysql:8.0. Resolved in Red Hat advisory RHSA-2026:25919 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-34271] Group Replication Plugin unspecified vulnerability (CPU Apr 2026)
Group Replication Plugin unspecified vulnerability (CPU Apr 2026). Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-772. Affected package(s): mysql:8.4, mysql, mysql8.4, mysql:8.0. Resolved in Red Hat advisory RHSA-2026:25919 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-22009] Optimizer unspecified vulnerability (CPU Apr 2026)
Optimizer unspecified vulnerability (CPU Apr 2026). Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected package(s): mysql:8.4, mysql, mysql8.4, mysql:8.0. Resolved in Red Hat advisory RHSA-2026:25919 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-21998] Optimizer unspecified vulnerability (CPU Apr 2026)
Optimizer unspecified vulnerability (CPU Apr 2026). Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-770. Affected package(s): mysql:8.4, mysql, mysql8.4, mysql:8.0. Resolved in Red Hat advisory RHSA-2026:25919 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-35239] DML unspecified vulnerability (CPU Apr 2026)
DML unspecified vulnerability (CPU Apr 2026). Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-772. Affected package(s): mysql:8.4, mysql, mysql8.4, mysql:8.0. Resolved in Red Hat advisory RHSA-2026:25919 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-34308] JSON unspecified vulnerability (CPU Apr 2026)
JSON unspecified vulnerability (CPU Apr 2026). Red Hat rates this moderate (CVSS 6.5). Weakness: CWE-770. Affected package(s): mysql:8.4, mysql, mysql8.4, mysql:8.0. Resolved in Red Hat advisory RHSA-2026:25919 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1.
Medium [CVE-2026-34293] DML unspecified vulnerability (CPU Apr 2026)
DML unspecified vulnerability (CPU Apr 2026). Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-770. Affected package(s): mysql, mysql:8.0. Resolved in Red Hat advisory RHSA-2026:25919 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9.
Medium [CVE-2026-34267] Optimizer unspecified vulnerability (CPU Apr 2026)
Optimizer unspecified vulnerability (CPU Apr 2026). Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-770. Affected package(s): mysql, mysql:8.0. Resolved in Red Hat advisory RHSA-2026:25919 — update the affected packages (`sudo dnf update`). Affected products named by the advisory: Red Hat Enterprise Linux 9.