Red Hat Linux Security Advisories & CVEs
514 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Critical [CVE-2026-87616] Improper initialization in Views
Improper initialization in Views. Red Hat rates this important (CVSS 9). Weakness: CWE-824.
Critical [CVE-2026-87648] Arbitrary code execution in Google Chrome due to use-after-free
Arbitrary code execution in Google Chrome due to use-after-free. Red Hat rates this important (CVSS 9). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Critical [CVE-2026-87500] ANGLE in Google Chrome: Arbitrary code execution via crafted HTML page
ANGLE in Google Chrome: Arbitrary code execution via crafted HTML page. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat package: webkitgtk4; and 1 more. Affected products named by the advisory: Red Hat package: webkit2gtk3.
Critical [CVE-2026-87654] Arbitrary code execution via buffer overflow in ANGLE
Arbitrary code execution via buffer overflow in ANGLE. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-120. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Critical [CVE-2026-87621] Google Chrome (ANGLE): Arbitrary Code Execution vulnerability
Google Chrome (ANGLE): Arbitrary Code Execution vulnerability. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Critical [CVE-2026-87604] ANGLE in Google Chrome: Arbitrary code execution via out-of-bounds read
ANGLE in Google Chrome: Arbitrary code execution via out-of-bounds read. Red Hat rates this important (CVSS 9). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Critical [CVE-2026-87512] Arbitrary code execution via use-after-free vulnerability in ANGLE
Arbitrary code execution via use-after-free vulnerability in ANGLE. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Critical [CVE-2026-78234] Service-CA signing oracle allows arbitrary-CN certificate issuance to namespace edit users
Service-CA signing oracle allows arbitrary-CN certificate issuance to namespace edit users. Red Hat rates this important (CVSS 9.9). Weakness: CWE-295. Red Hat lists fixing advisory RHSA-2026:66120 with package rhbac-4/hawtio-operator-bundle:2.0.1-8, rhbac-4/hawtio-rhel9-operator:2.0.1-10. Affected product named by the advisory: Red Hat build of Apache Camel - HawtIO 4.
Critical [CVE-2026-18922] SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property
SASL PLAIN authentication allows privilege escalation to Directory Manager via stale identity in Cyrus SASL auxiliary property. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-287. Red Hat lists fixing advisory RHSA-2026:64783 with package 389-ds-base-0:2.4.5-29.el9_4, 389-ds-base-0:2.6.1-24.el9_6, 389-ds-base-0:3.0.6-21.el10_0, redhat-ds:12-9020020260903155914.1674d574. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.
Critical [CVE-2026-76578] unauthenticated LDAP client can obtain administrator credentials via the self-managed-token ACI
unauthenticated LDAP client can obtain administrator credentials via the self-managed-token ACI. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-306. Red Hat lists fixing advisory RHSA-2026:72279 with package ipa-0:4.13.4-1.el9_8, ipa-0:4.13.4-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
Critical [CVE-2026-85595] Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth
Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-305. Affected product named by the advisory: Red Hat OpenShift Dev Spaces.
Critical [CVE-2026-76595] Unsafe YAML deserialization of associate-editable Task playbook (yaml.Loader)
Unsafe YAML deserialization of associate-editable Task playbook (yaml. Loader). Red Hat rates this critical. Weakness: CWE-502.
Critical [CVE-2026-84324] Use after free in Proxy
Use after free in Proxy in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to execute arbitrary code outside the sandbox via crafted network traffic. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-825.
Critical [CVE-2026-77849] Hardcoded Grafana admin credentials (admin / admin) in `pkg/specsyncer`
Hardcoded Grafana admin credentials (admin / admin) in `pkg/specsyncer`. Red Hat rates this important (CVSS 9.8). Weakness: CWE-798. Red Hat lists fixing advisory RHSA-2026:68515 with package multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1788376193, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1788441983, multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1788375682. Affected product named by the advisory: Multicluster Global Hub.
Critical [CVE-2026-54745] Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABLE_AUTHZ=true
Unauthenticated SSRF and HTTP smuggling in Kubeflow Pipelines frontend /_proxy/ route, bypasses ENABLE_AUTHZ=true. Red Hat rates this important (CVSS 10). Weakness: CWE-918.
Critical [CVE-2026-42007] Arbitrary Code Execution via Sieve editheader use-after-free
Arbitrary Code Execution via Sieve editheader use-after-free. Red Hat rates this important (CVSS 9.1). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat package: dovecot.
Critical [CVE-2026-47884] Remote Code Execution via improper path limitation in XsltView
Remote Code Execution via improper path limitation in XsltView. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-22. Affected products named by the advisory: Red Hat build of Apache Camel for Spring Boot 4; Red Hat build of Apache Camel - HawtIO 4; Red Hat Fuse 7; Red Hat OpenShift Dev Spaces; and 1 more. Affected products named by the advisory: Red Hat Single Sign-On 7.
Critical [CVE-2026-79269] Web origin policy bypass via uninitialized resource in ANGLE
Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium) A flaw was found in ANGLE, a component of Chromium. This could potentially allow the attacker to bypass the web origin policy, leading to unauthorized access to sensitive information or actions. Red Hat severity: Critical — CVSS 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N). Weakness: CWE-824. Affected Red Hat products: Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Critical [CVE-2026-79155] Race condition in FileSystem
Race condition in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-368.
Critical [CVE-2026-78939] Use after free in Chromecast
Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High) Upstream bug(s): Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory. Red Hat severity: Important — CVSS 9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H). Weakness: CWE-825.