Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4448 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.5Red Hat

High [CVE-2026-92028] Use-after-free in the DOM: Core & HTML component

Use-after-free in the DOM: Core & HTML component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92028
Unclassified
Sep 15, 2026
High7.5Red Hat

High [CVE-2026-92027] Use-after-free in the DOM: Streams component

Use-after-free in the DOM: Streams component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92027
Unclassified
Sep 15, 2026
High7.5Red Hat

High [CVE-2026-92026] Use-after-free in the Networking component

Use-after-free in the Networking component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92026
Unclassified
Sep 15, 2026
High7.5Red Hat

High [CVE-2026-92025] Use-after-free in the DOM: Navigation component

Use-after-free in the DOM: Navigation component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92025
Unclassified
Sep 15, 2026
High7.5Red Hat

High [CVE-2026-92023] Use-after-free in the XML component

Use-after-free in the XML component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92023
Unclassified
Sep 15, 2026
High7.5Red Hat

High [CVE-2026-92022] Use-after-free in the DOM: HTML Parser component

Use-after-free in the DOM: HTML Parser component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92022
Unclassified
Sep 15, 2026
High7.5Red Hat

High [CVE-2026-92021] Use-after-free in the JavaScript Engine: JIT component

Use-after-free in the JavaScript Engine: JIT component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92021
Unclassified
Sep 15, 2026
High7.5Red Hat

High [CVE-2026-92020] Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component

Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92020
Unclassified
Sep 15, 2026
High7.5Red Hat

High [CVE-2026-92019] Mitigation bypass in the Remote Settings Client component

Mitigation bypass in the Remote Settings Client component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-807. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92019
Unclassified
Sep 15, 2026
High7.5Red Hat

High [CVE-2026-92018] Sandbox escape in the DOM: Core & HTML component

Sandbox escape in the DOM: Core & HTML component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-791. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92018
Unclassified
Sep 15, 2026
High7.5Red Hat

High [CVE-2026-92017] Privilege escalation in the DOM: Service Workers component

Privilege escalation in the DOM: Service Workers component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92017
Unclassified
Sep 15, 2026
High7.5Red Hat

High [CVE-2026-92016] Use-after-free in the Disability Access APIs component

Use-after-free in the Disability Access APIs component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92016
Unclassified
Sep 15, 2026
High7.5Red Hat

High [CVE-2026-92015] Privilege escalation in the WebExtensions component

Privilege escalation in the WebExtensions component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92015
Unclassified
Sep 15, 2026
High7.5Red Hat

High [CVE-2026-92014] Privilege escalation due to incorrect boundary conditions in the Graphics component

Privilege escalation due to incorrect boundary conditions in the Graphics component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92014
Unclassified
Sep 15, 2026
High7.5Red Hat

High [CVE-2026-92013] Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92013
Unclassified
Sep 15, 2026
High7.5Red Hat

High [CVE-2026-92012] Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-266. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92012
Unclassified
Sep 15, 2026
High7.5Red Hat

High [CVE-2026-92006] Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component

Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-653. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92006
Unclassified
Sep 15, 2026
High7.5Red Hat

High [CVE-2026-92005] Use-after-free in the Audio/Video: Web Codecs component

Use-after-free in the Audio/Video: Web Codecs component. Red Hat rates this important (CVSS 7.5). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:73130 with package thunderbird-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el9_8, firefox-0:140.16.0-1.el8_10, thunderbird-0:140.16.0-1.el8_10. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 10.

CVE-2026-92005
Unclassified
Sep 15, 2026
High7.3Red Hat

High [CVE-2026-75092] scan_mysql runs mysqld --validate-config as root and can load mysql-writable plugins

scan_mysql runs mysqld --validate-config as root and can load mysql-writable plugins. Red Hat rates this important (CVSS 7.3). Weakness: CWE-250. Red Hat lists fixing advisory RHSA-2026:67609 with package leapp-repository-0:0.24.0-1.el9_8.1, leapp-repository-0:0.22.0-1.el9_6.2. Affected product named by the advisory: Red Hat Enterprise Linux 9.

CVE-2026-75092
Unclassified
Sep 15, 2026
High7.3Red Hat

High [CVE-2026-90852] luben zstd-jni: Remote use-after-free vulnerability in dictionary sharing

luben zstd-jni: Remote use-after-free vulnerability in dictionary sharing. Red Hat rates this important (CVSS 7.3). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 10 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 6 more.

CVE-2026-90852
Red Hat Enterprise Linux
Sep 15, 2026

← All vendors