Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

4597 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

High7.7Red Hat

High [CVE-2026-87825] Data corruption or denial of service via use-after-free vulnerability

Data corruption or denial of service via use-after-free vulnerability. Red Hat rates this important (CVSS 7.7). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 9 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 5 more.

CVE-2026-87825
Red Hat Enterprise Linux
Sep 9, 2026
High8.2Red Hat

High [CVE-2026-87823] Denial of Service or Information Disclosure via out-of-bounds read

Denial of Service or Information Disclosure via out-of-bounds read. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Affected product named by the advisory: Red Hat Ceph Storage 9.

CVE-2026-87823
Unclassified
Sep 9, 2026
High7.5Red Hat

High [CVE-2026-87822] Denial of Service via NaN centroid injection during deserialization

Denial of Service via NaN centroid injection during deserialization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-502. Affected product named by the advisory: Red Hat Offline Knowledge Portal.

CVE-2026-87822
Unclassified
Sep 9, 2026
High8.1Red Hat

High [CVE-2026-18147] Cross-Site Scripting vulnerability allows arbitrary code execution via crafted URL

Cross-Site Scripting vulnerability allows arbitrary code execution via crafted URL. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:72279 with package ipa-0:4.13.4-1.el9_8, ipa-0:4.13.4-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.

CVE-2026-18147
Unclassified
Sep 9, 2026
High7.5Vendor: MediumRed Hat

High [CVE-2026-87853] IdP authentication prefix comparison allows cross-user impersonation

IdP authentication prefix comparison allows cross-user impersonation. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-187. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: sssd.

CVE-2026-87853
Unclassified
Sep 9, 2026
High8.8Red Hat

High [CVE-2026-56711] VLC media player: Arbitrary code execution via integer overflow in picture allocation

VLC media player: Arbitrary code execution via integer overflow in picture allocation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-56711
Unclassified
Sep 9, 2026
High8.8Red Hat

High [CVE-2026-87817] Remote Code Execution via Git directory impersonation

Remote Code Execution via Git directory impersonation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:68764 with package satellite/iop-vmaas-rhel9:1789611858, ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, ansible-automation-platform-25/controller-rhel8:1789607021. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more.

CVE-2026-87817
Unclassified
Sep 9, 2026
High8.2Red Hat

High [CVE-2026-87795] Out-of-bounds read in ZstdDictCompress constructor leads to denial of service

Out-of-bounds read in ZstdDictCompress constructor leads to denial of service. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 9 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 5 more.

CVE-2026-87795
Red Hat Enterprise Linux
Sep 9, 2026
High7.4Red Hat

High [CVE-2026-87586] ANGLE in Google Chrome: Information disclosure via crafted HTML page

ANGLE in Google Chrome: Information disclosure via crafted HTML page. Red Hat rates this important (CVSS 7.4). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-87586
Red Hat Enterprise Linux
Sep 9, 2026
High7.4Red Hat

High [CVE-2026-87468] Incorrect authorization in Isolated

Incorrect authorization in Isolated. Red Hat rates this important (CVSS 7.4). Weakness: CWE-551.

CVE-2026-87468
Unclassified
Sep 9, 2026
High8.7Red Hat

High [CVE-2026-87471] Incorrect authorization in ServiceWorker

Incorrect authorization in ServiceWorker. Red Hat rates this important (CVSS 8.7). Weakness: CWE-266.

CVE-2026-87471
Unclassified
Sep 9, 2026
High8.8Red Hat

High [CVE-2026-87588] Use after free in Chromecast

Use after free in Chromecast. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.

CVE-2026-87588
Unclassified
Sep 9, 2026
High8.8Red Hat

High [CVE-2026-87636] Type confusion in XML

Type confusion in XML. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843.

CVE-2026-87636
Unclassified
Sep 9, 2026
High7.9Red Hat

High [CVE-2026-87498] Missing authorization in WebUI

Missing authorization in WebUI. Red Hat rates this important (CVSS 7.9). Weakness: CWE-346.

CVE-2026-87498
Unclassified
Sep 9, 2026
High8.7Red Hat

High [CVE-2026-87499] Incorrect authorization in Network

Incorrect authorization in Network. Red Hat rates this important (CVSS 8.7). Weakness: CWE-653.

CVE-2026-87499
Unclassified
Sep 9, 2026
High7.4Red Hat

High [CVE-2026-87564] Type confusion in V8

Type confusion in V8. Red Hat rates this important (CVSS 7.4). Weakness: CWE-843.

CVE-2026-87564
Unclassified
Sep 9, 2026
High8.8Red Hat

High [CVE-2026-87460] Use after free in Platform

Use after free in Platform. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.

CVE-2026-87460
Unclassified
Sep 9, 2026
High7.4Red Hat

High [CVE-2026-87596] ANGLE in Google Chrome: Information disclosure via out-of-bounds read

ANGLE in Google Chrome: Information disclosure via out-of-bounds read. Red Hat rates this important (CVSS 7.4). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.

CVE-2026-87596
Red Hat Enterprise Linux
Sep 9, 2026
High8.8Red Hat

High [CVE-2026-87444] Memory corruption in Codecs

Memory corruption in Codecs. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.

CVE-2026-87444
Unclassified
Sep 9, 2026
High8.8Red Hat

High [CVE-2026-87766] symlink traversal via /oldroot allows writing files outside sandbox during setup

symlink traversal via /oldroot allows writing files outside sandbox during setup. Red Hat rates this important (CVSS 8.8). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.

CVE-2026-87766
Unclassified
Sep 9, 2026

← All vendors