Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

514 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-87616] Improper initialization in Views

Improper initialization in Views. Red Hat rates this important (CVSS 9). Weakness: CWE-824.

CVE-2026-87616
Unclassified
Sep 9, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-87648] Arbitrary code execution in Google Chrome due to use-after-free

Arbitrary code execution in Google Chrome due to use-after-free. Red Hat rates this important (CVSS 9). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-87648
Red Hat Enterprise Linux
Sep 9, 2026
Critical9.6Red Hat

Critical [CVE-2026-87500] ANGLE in Google Chrome: Arbitrary code execution via crafted HTML page

ANGLE in Google Chrome: Arbitrary code execution via crafted HTML page. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: webkitgtk4; and 1 more. Affected products named by the advisory: Red Hat package: webkit2gtk3.

CVE-2026-87500
Red Hat Enterprise Linux
Sep 9, 2026
Critical9.6Red Hat

Critical [CVE-2026-87654] Arbitrary code execution via buffer overflow in ANGLE

Arbitrary code execution via buffer overflow in ANGLE. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-87654
Red Hat Enterprise Linux
Sep 9, 2026
Critical9.6Red Hat

Critical [CVE-2026-87621] Google Chrome (ANGLE): Arbitrary Code Execution vulnerability

Google Chrome (ANGLE): Arbitrary Code Execution vulnerability. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-87621
Red Hat Enterprise Linux
Sep 9, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-87604] ANGLE in Google Chrome: Arbitrary code execution via out-of-bounds read

ANGLE in Google Chrome: Arbitrary code execution via out-of-bounds read. Red Hat rates this important (CVSS 9). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-87604
Red Hat Enterprise Linux
Sep 9, 2026
Critical9.6Red Hat

Critical [CVE-2026-87512] Arbitrary code execution via use-after-free vulnerability in ANGLE

Arbitrary code execution via use-after-free vulnerability in ANGLE. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-87512
Red Hat Enterprise Linux
Sep 9, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-78234] Service-CA signing oracle allows arbitrary-CN certificate issuance to namespace edit users

Service-CA signing oracle allows arbitrary-CN certificate issuance to namespace edit users. Red Hat rates this important (CVSS 9.9). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:66120 with package rhbac-4/hawtio-operator-bundle:2.0.1-8, rhbac-4/hawtio-rhel9-operator:2.0.1-10. Affected product named by the advisory: Red Hat build of Apache Camel - HawtIO 4.

CVE-2026-78234
Unclassified
Sep 8, 2026
Critical9.8Red Hat

Critical [CVE-2026-18922] SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property

SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-287. Red Hat lists fixing advisory RHSA-2026:64783 with package 389-ds-base-0:2.4.5-29.el9_4, 389-ds-base-0:2.6.1-24.el9_6, 389-ds-base-0:3.0.6-21.el10_0, redhat-ds:12-9020020260903155914.1674d574. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.

CVE-2026-18922
Unclassified
Sep 7, 2026
Critical9.8Red Hat

Critical [CVE-2026-76578] unauthenticated LDAP client can obtain administrator credentials via the self-managed-token ACI

unauthenticated LDAP client can obtain administrator credentials via the self-managed-token ACI. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:72279 with package ipa-0:4.13.4-1.el9_8, ipa-0:4.13.4-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-76578
Unclassified
Sep 7, 2026
Critical9.1Red Hat

Critical [CVE-2026-85595] Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth

Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-305. Affected product named by the advisory: Red Hat OpenShift Dev Spaces.

CVE-2026-85595
Unclassified
Sep 4, 2026
CriticalRed Hat

Critical [CVE-2026-76595] Unsafe YAML deserialization of associate-editable Task playbook (yaml.Loader)

Unsafe YAML deserialization of associate-editable Task playbook (yaml. Loader). Red Hat rates this critical. Weakness: CWE-502.

CVE-2026-76595
Unclassified
Sep 2, 2026
Critical10.0Vendor: HighRed Hat

Critical [CVE-2026-84324] Use after free in Proxy

Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-84324
Unclassified
Sep 1, 2026
Critical9.8Vendor: HighRed Hat

Critical [CVE-2026-77849] Hardcoded Grafana admin credentials (admin / admin) in `pkg/specsyncer`

Hardcoded Grafana admin credentials (admin / admin) in `pkg/specsyncer`. Red Hat rates this important (CVSS 9.8). Weakness: CWE-798. Red Hat lists fixing advisory RHSA-2026:68515 with package multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1788376193, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1788441983, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1788375682. Affected product named by the advisory: Multicluster Global Hub.

CVE-2026-77849
Unclassified
Aug 31, 2026
Critical10.0Vendor: HighRed Hat

Critical [CVE-2026-54745] Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABLE_AUTHZ=true

Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABLE_AUTHZ=true. Red Hat rates this important (CVSS 10). Weakness: CWE-918.

CVE-2026-54745
Unclassified
Aug 28, 2026
Critical9.1Vendor: HighRed Hat

Critical [CVE-2026-42007] Arbitrary Code Execution via Sieve editheader use-after-free

Arbitrary Code Execution via Sieve editheader use-after-free. Red Hat rates this important (CVSS 9.1). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.

CVE-2026-42007
Red Hat Enterprise Linux
Aug 28, 2026
Critical9.8Red Hat

Critical [CVE-2026-47884] Remote Code Execution via improper path limitation in XsltView

Remote Code Execution via improper path limitation in XsltView. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-22. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apache Camel - HawtIO 4; Red Hat Fuse 7; Red Hat OpenShift Dev Spaces; and 1 more. Affected products named by the advisory: Red Hat Single Sign-On 7.

CVE-2026-47884
Unclassified
Aug 27, 2026
Critical9.3Red Hat

Critical [CVE-2026-79269] Web origin policy bypass via uninitialized resource in ANGLE

Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) A flaw was found in ANGLE, a component of Chromium. This could potentially allow the attacker to bypass the web origin policy, leading to unauthorized access to sensitive information or actions. Red Hat severity: Critical — CVSS 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N). Weakness: CWE-824. Affected Red Hat products: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-79269
Red Hat Enterprise Linux
Aug 25, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-79155] Race condition in FileSystem

Race condition in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-368.

CVE-2026-79155
Unclassified
Aug 25, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-78939] Use after free in Chromecast

Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.

CVE-2026-78939
Unclassified
Aug 25, 2026

← All vendors