Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4440 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High8.8Red Hat

High [CVE-2026-91098] Multiple vulnerabilities allow remote code execution and privilege escalation

Multiple vulnerabilities allow remote code execution and privilege escalation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-494. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.

CVE-2026-91098
Red Hat Enterprise Linux
Sep 16, 2026
High7.5Red Hat

High [CVE-2026-86003] Unauthorized DNS record modification via unvalidated DNS updates

Unauthorized DNS record modification via unvalidated DNS updates. Red Hat rates this important (CVSS 7.5). Weakness: CWE-306. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Connectivity Link 1; Red Hat OpenShift Container Platform 4.

CVE-2026-86003
Unclassified
Sep 16, 2026
High8.8Red Hat

High [CVE-2026-91097] Multiple vulnerabilities enable remote code execution and privilege escalation

Multiple vulnerabilities enable remote code execution and privilege escalation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-94. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: hplip.

CVE-2026-91097
Red Hat Enterprise Linux
Sep 16, 2026
High7.5Red Hat

High [CVE-2026-82399] Denial of Service due to unauthenticated memory exhaustion in custom transports

Denial of Service due to unauthenticated memory exhaustion in custom transports. Red Hat rates this important (CVSS 7.5). Weakness: CWE-1050. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat Connectivity Link 1; Red Hat OpenShift Container Platform 4.

CVE-2026-82399
Unclassified
Sep 16, 2026
High7.5Red Hat

High [CVE-2026-75516] RabbitMQ Java client: Denial of Service via oversized frames

RabbitMQ Java client: Denial of Service via oversized frames. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Affected products named by the advisory: Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat Fuse 7.

CVE-2026-75516
Unclassified
Sep 16, 2026
High7.5Red Hat

High [CVE-2026-46352] Denial of Service via fragmented encapsulated traffic

Denial of Service via fragmented encapsulated traffic. Red Hat rates this important (CVSS 7.5). Weakness: CWE-833.

CVE-2026-46352
Unclassified
Sep 16, 2026
High7.4Red Hat

High [CVE-2026-42784] Cryptographic integrity compromise via key flag confusion

Cryptographic integrity compromise via key flag confusion. Red Hat rates this important (CVSS 7.4). Weakness: CWE-347. Red Hat lists fixing advisory RHSA-2026:42902 with package rust-podman-sequoia-main-0.3.2-4.hum1. Affected products named by the advisory: Red Hat Hardened Images; Confidential Compute Attestation; Red Hat Ansible Automation Platform 2; Red Hat Enterprise Linux 10; and 8 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4; Red Hat Satellite 6; Red Hat Trusted Profile Analyzer.

CVE-2026-42784
Unclassified
Sep 16, 2026
High7.2Red Hat

High [CVE-2026-17526] Privilege escalation via impersonation role allows takeover of realm administrator accounts

Privilege escalation via impersonation role allows takeover of realm administrator accounts. Red Hat rates this important (CVSS 7.2). Weakness: CWE-862. Red Hat lists fixing advisory RHSA-2026:68277 with package rhbk-keycloak-rhel9/rhbk-keycloak-rhel9, rhbk/keycloak-rhel9:26.6-20, keycloak-services, rhbk-openshift-rhel9/rhbk-openshift-rhel9. Affected products named by the advisory: Red Hat build of Keycloak 26.4.16; Red Hat build of Keycloak 26.6.7.

CVE-2026-17526
Unclassified
Sep 16, 2026
High7.5Red Hat

High [CVE-2026-79651] unauthenticated DoS via unbounded locale caching

unauthenticated DoS via unbounded locale caching. Red Hat rates this important (CVSS 7.5). Weakness: CWE-400. Red Hat lists fixing advisory RHSA-2026:68277 with package rhbk/keycloak-rhel9, rhbk/keycloak-rhel9:26.6-20, keycloak-services, keycloak/rhbk-openshift-rhel9. Affected products named by the advisory: Red Hat build of Keycloak 26.4; Red Hat build of Keycloak 26.6.

CVE-2026-79651
Unclassified
Sep 16, 2026
High8.1Red Hat

High [CVE-2026-15573 +1] Incomplete fix for CVE-2026-15573 allows policy enforcer bypass via percent-encoded URI segments

Incomplete fix for CVE-2026-15573 allows policy enforcer bypass via percent-encoded URI segments. Red Hat rates this important (CVSS 8.1). Weakness: CWE-862. Red Hat lists fixing advisory RHSA-2026:68277 with package rhbk/keycloak-rhel9:26.6-20, keycloak-services, keycloak/rhbk-openshift-rhel9, rhbk/keycloak-rhel9-operator:26.6-20. Affected products named by the advisory: Red Hat build of Keycloak 26.4.16; Red Hat build of Keycloak 26.6.7.

CVE-2026-15573CVE-2026-74909
Unclassified
Sep 16, 2026
High7.5Red Hat

High [CVE-2026-18212] SAML Redirect DEFLATE helpers leak native zlib state

SAML Redirect DEFLATE helpers leak native zlib state. Red Hat rates this important (CVSS 7.5). Weakness: CWE-401. Red Hat lists fixing advisory RHSA-2026:68277 with package rhbk-keycloak-rhel9/rhbk-keycloak-rhel9, rhbk/keycloak-rhel9:26.6-20, keycloak-services, rhbk-openshift-rhel9/rhbk-openshift-rhel9. Affected products named by the advisory: Red Hat build of Keycloak 26.4.16; Red Hat build of Keycloak 26.6.7; Red Hat Data Grid 8; Red Hat Single Sign-On 7.

CVE-2026-18212
Unclassified
Sep 16, 2026
High8.2Red Hat

High [CVE-2026-63127] Token impersonation via missing OAuth resource field validation

Token impersonation via missing OAuth resource field validation. Red Hat rates this important (CVSS 8.2). Weakness: CWE-289. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: goose.

CVE-2026-63127
Red Hat Enterprise Linux
Sep 16, 2026
High7.5Red Hat

High [CVE-2026-63128] Denial of Service via unauthenticated session table leak

Denial of Service via unauthenticated session table leak. Red Hat rates this important (CVSS 7.5). Weakness: CWE-772. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat package: goose.

CVE-2026-63128
Red Hat Enterprise Linux
Sep 16, 2026
High7.5Red Hat

High [CVE-2026-77409] RabbitMQ amqp091-go: Denial of Service due to synchronous event channel blocking

RabbitMQ amqp091-go: Denial of Service due to synchronous event channel blocking. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:68290 with package opentelemetry-collector-contrib-main-0.161.0-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Multicluster Global Hub; OpenShift Serverless; Red Hat Advanced Cluster Management for Kubernetes 2; and 2 more. Affected products named by the advisory: Red Hat OpenStack Platform 18.0; Red Hat Quay 3.

CVE-2026-77409
Unclassified
Sep 16, 2026
High7.5Red Hat

High [CVE-2026-77412] RabbitMQ amqp091-go: Denial of Service via Malicious AMQP Field Length

RabbitMQ amqp091-go: Denial of Service via Malicious AMQP Field Length. Red Hat rates this important (CVSS 7.5). Weakness: CWE-805. Red Hat lists fixing advisory RHSA-2026:68290 with package opentelemetry-collector-contrib-main-0.161.0-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Multicluster Global Hub; OpenShift Serverless; and 3 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat OpenStack Platform 18.0; Red Hat Quay 3.

CVE-2026-77412
Unclassified
Sep 16, 2026
High8.8Red Hat

High [CVE-2026-77404] RabbitMQ amqp091-go: Connection configuration overwrite via unsanitized TLS path parameter injection

RabbitMQ amqp091-go: Connection configuration overwrite via unsanitized TLS path parameter injection. Red Hat rates this important (CVSS 8.8). Weakness: CWE-140. Red Hat lists fixing advisory RHSA-2026:68290 with package opentelemetry-collector-contrib-main-0.161.0-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Multicluster Global Hub; OpenShift Serverless; and 3 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat OpenStack Platform 18.0; Red Hat Quay 3.

CVE-2026-77404
Unclassified
Sep 16, 2026
High7.5Red Hat

High [CVE-2026-77410] RabbitMQ amqp091-go: Denial of Service via unbounded body buffer allocation

RabbitMQ amqp091-go: Denial of Service via unbounded body buffer allocation. Red Hat rates this important (CVSS 7.5). Weakness: CWE-770. Red Hat lists fixing advisory RHSA-2026:68290 with package opentelemetry-collector-contrib-main-0.161.0-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Custom Metric Autoscaler operator for Red Hat Openshift; Multicluster Global Hub; OpenShift Serverless; and 3 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat OpenStack Platform 18.0; Red Hat Quay 3.

CVE-2026-77410
Unclassified
Sep 16, 2026
High7.5Red Hat

High [CVE-2026-77406] RabbitMQ amqp091-go: Denial of Service via signed-to-unsigned integer casting

RabbitMQ amqp091-go: Denial of Service via signed-to-unsigned integer casting. Red Hat rates this important (CVSS 7.5). Weakness: CWE-190. Red Hat lists fixing advisory RHSA-2026:68290 with package opentelemetry-collector-contrib-main-0.161.0-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Multicluster Global Hub; OpenShift Serverless; and 3 more. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat OpenStack Platform 18.0; Red Hat Quay 3.

CVE-2026-77406
Unclassified
Sep 16, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-77403] RabbitMQ amqp091-go: Denial of Service via AMQP frame size negotiation

RabbitMQ amqp091-go: Denial of Service via AMQP frame size negotiation. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-839. Red Hat lists fixing advisory RHSA-2026:68290 with package opentelemetry-collector-contrib-main-0.161.0-0.1.hum1. Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; Custom Metric Autoscaler operator for Red Hat Openshift; Multicluster Global Hub; and 4 more. Affected products named by the advisory: OpenShift Serverless; Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat OpenStack Platform 18.0; Red Hat Quay 3.

CVE-2026-77403
Unclassified
Sep 16, 2026
High7.4Red Hat

High [CVE-2026-90997] Replay protection bypass leads to unauthorized access via database driver semantics mismatch

Replay protection bypass leads to unauthorized access via database driver semantics mismatch. Red Hat rates this important (CVSS 7.4). Weakness: CWE-294.

CVE-2026-90997
Unclassified
Sep 16, 2026

← All vendors