Red Hat Linux Security Advisories & CVEs
4597 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2026-87825] Data corruption or denial of service via use-after-free vulnerability
Data corruption or denial of service via use-after-free vulnerability. Red Hat rates this important (CVSS 7.7). Weakness: CWE-825. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 9 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 5 more.
High [CVE-2026-87823] Denial of Service or Information Disclosure via out-of-bounds read
Denial of Service or Information Disclosure via out-of-bounds read. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Affected product named by the advisory: Red Hat Ceph Storage 9.
High [CVE-2026-87822] Denial of Service via NaN centroid injection during deserialization
Denial of Service via NaN centroid injection during deserialization. Red Hat rates this important (CVSS 7.5). Weakness: CWE-502. Affected product named by the advisory: Red Hat Offline Knowledge Portal.
High [CVE-2026-18147] Cross-Site Scripting vulnerability allows arbitrary code execution via crafted URL
Cross-Site Scripting vulnerability allows arbitrary code execution via crafted URL. Red Hat rates this important (CVSS 8.1). Weakness: CWE-79. Red Hat lists fixing advisory RHSA-2026:72279 with package ipa-0:4.13.4-1.el9_8, ipa-0:4.13.4-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 10.
High [CVE-2026-87853] IdP authentication prefix comparison allows cross-user impersonation
IdP authentication prefix comparison allows cross-user impersonation. Red Hat rates this moderate (CVSS 7.5). Weakness: CWE-187. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat package: sssd.
High [CVE-2026-56711] VLC media player: Arbitrary code execution via integer overflow in picture allocation
VLC media player: Arbitrary code execution via integer overflow in picture allocation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.
High [CVE-2026-87817] Remote Code Execution via Git directory impersonation
Remote Code Execution via Git directory impersonation. Red Hat rates this important (CVSS 8.8). Weakness: CWE-22. Red Hat lists fixing advisory RHSA-2026:68764 with package satellite/iop-vmaas-rhel9:1789611858, ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap, ansible-automation-platform-25/controller-rhel8:1789607021. Affected products named by the advisory: Exploit Intelligence; Migration Toolkit for Applications 8; Red Hat AI Inference Server; Red Hat Ansible Automation Platform 2; and 5 more. Affected products named by the advisory: Red Hat Enterprise Linux AI (RHEL AI) 3; Red Hat OpenShift AI (RHOAI); Red Hat OpenStack Platform 16.2; Red Hat OpenStack Platform 17.1; and 1 more.
High [CVE-2026-87795] Out-of-bounds read in ZstdDictCompress constructor leads to denial of service
Out-of-bounds read in ZstdDictCompress constructor leads to denial of service. Red Hat rates this important (CVSS 8.2). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:71675 with package zstd-jni. Affected products named by the advisory: Exploit Intelligence; OpenShift Developer Tools and Services; Red Hat build of Apache Camel 4 for Quarkus 3; Red Hat build of Apache Camel for Spring Boot 4; and 9 more. Affected products named by the advisory: Red Hat build of Apicurio Registry 3; Red Hat build of Debezium 3; Red Hat build of Quarkus; Red Hat Ceph Storage 9; and 5 more.
High [CVE-2026-87586] ANGLE in Google Chrome: Information disclosure via crafted HTML page
ANGLE in Google Chrome: Information disclosure via crafted HTML page. Red Hat rates this important (CVSS 7.4). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
High [CVE-2026-87468] Incorrect authorization in Isolated
Incorrect authorization in Isolated. Red Hat rates this important (CVSS 7.4). Weakness: CWE-551.
High [CVE-2026-87471] Incorrect authorization in ServiceWorker
Incorrect authorization in ServiceWorker. Red Hat rates this important (CVSS 8.7). Weakness: CWE-266.
High [CVE-2026-87588] Use after free in Chromecast
Use after free in Chromecast. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-87636] Type confusion in XML
Type confusion in XML. Red Hat rates this important (CVSS 8.8). Weakness: CWE-843.
High [CVE-2026-87498] Missing authorization in WebUI
Missing authorization in WebUI. Red Hat rates this important (CVSS 7.9). Weakness: CWE-346.
High [CVE-2026-87499] Incorrect authorization in Network
Incorrect authorization in Network. Red Hat rates this important (CVSS 8.7). Weakness: CWE-653.
High [CVE-2026-87564] Type confusion in V8
Type confusion in V8. Red Hat rates this important (CVSS 7.4). Weakness: CWE-843.
High [CVE-2026-87460] Use after free in Platform
Use after free in Platform. Red Hat rates this important (CVSS 8.8). Weakness: CWE-825.
High [CVE-2026-87596] ANGLE in Google Chrome: Information disclosure via out-of-bounds read
ANGLE in Google Chrome: Information disclosure via out-of-bounds read. Red Hat rates this important (CVSS 7.4). Weakness: CWE-125. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 2 more. Affected products named by the advisory: Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
High [CVE-2026-87444] Memory corruption in Codecs
Memory corruption in Codecs. Red Hat rates this important (CVSS 8.8). Weakness: CWE-787.
High [CVE-2026-87766] symlink traversal via /oldroot allows writing files outside sandbox during setup
symlink traversal via /oldroot allows writing files outside sandbox during setup. Red Hat rates this important (CVSS 8.8). Weakness: CWE-59. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.