Red Hat Linux Security Advisories & CVEs
5472 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Linux release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Linux advisories
Medium [CVE-2026-60747] Replication unspecified vulnerability (CPU Jul 2026)
Replication unspecified vulnerability (CPU Jul 2026). Red Hat rates this moderate (CVSS 6.2). Weakness: CWE-770.
Medium [CVE-2026-47023] Replication unspecified vulnerability (CPU Jul 2026)
Replication unspecified vulnerability (CPU Jul 2026). Red Hat rates this moderate (CVSS 4.9). Weakness: CWE-770.
Medium [CVE-2026-60183] Clone Plugin unspecified vulnerability (CPU Jul 2026)
Clone Plugin unspecified vulnerability (CPU Jul 2026). Red Hat rates this moderate (CVSS 6.4). Weakness: CWE-266.
Medium [CVE-2026-60585] Replication unspecified vulnerability (CPU Jul 2026)
Replication unspecified vulnerability (CPU Jul 2026). Red Hat rates this moderate (CVSS 6.6). Weakness: CWE-266.
Low [CVE-2026-16517] Signed Integer Overflow in archive_write_zip_header
A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the addition of the encryption overhead to the entry size overflows int64_t, resulting in undefined behavior. This could lead to incorrect Zip64 extension decisions or potential memory corruption. Red Hat Product Security rates this issue as Low severity. The vulnerability is in the ZIP write path only and requires both ZIP encryption to be enabled and a file size near INT64_MAX, making real-world exploitation highly unlikely. The resulting undefined behavior could theoretically cause incorrect Zip64 extension decisions or a crash, but the conditions are too contrived for practical exploitation. Weakness: CWE-190. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat fixing advisory: RHSA-2026:43818.
Low [CVE-2026-47010] Enhance JPEG handling (Oracle CPU 2026-07)
Enhance JPEG handling (Oracle CPU 2026-07). Red Hat rates this low (CVSS 3.7). Weakness: CWE-787. Red Hat lists fixing advisory RHSA-2026:50281 with package java-21-openjdk-1:21.0.12.0.8-1.1.el8, java-21-openjdk-1:21.0.12.0.8-1.1.el9, java-25-openjdk-windows, java-11-openjdk-1:11.0.32.0.9-1.el9. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.
Low [CVE-2026-47059] Enhance AWT ImagingLib (Oracle CPU 2026-07)
Enhance AWT ImagingLib (Oracle CPU 2026-07). Red Hat rates this low (CVSS 3.7). Weakness: CWE-476. Red Hat lists fixing advisory RHSA-2026:50281 with package java-21-openjdk-1:21.0.12.0.8-1.1.el8, java-21-openjdk-1:21.0.12.0.8-1.1.el9, java-25-openjdk-windows, java-11-openjdk-1:11.0.32.0.9-1.el9. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 7.
Low [CVE-2026-12547] Libsoup: information disclosure in libsoup via soupauthmanager proxy credential leak on proxy switch
SoupAuthManager caches proxy authentication credentials without scoping them to the proxy authority (host:port). When the proxy configuration changes (e.g., via system settings or WPAD), cached Proxy-Authorization headers from the previous proxy are sent to the new proxy, leaking credentials. This vulnerability is deemed LOW because it requires the user changing the desktop proxy settings from an authenticated proxy to the attacker's proxy. Red Hat severity: Low — CVSS 3.4 (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:N/A:N). Weakness: CWE-201. Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE.
Low [CVE-2026-59849] denial of service via automatic certificate authentication loop
denial of service via automatic certificate authentication loop. Red Hat rates this low (CVSS 3.1). Weakness: CWE-835. Red Hat lists fixing advisory RHSA-2026:42922 with package libssh-main-0.12.1-4.hum1.
Low [CVE-2026-59846] information disclosure via ProxyCommand %r username expansion
information disclosure via ProxyCommand %r username expansion. Red Hat rates this low (CVSS 3.9). Red Hat lists fixing advisory RHSA-2026:42922 with package libssh-main-0.12.1-4.hum1.
Low [CVE-2026-16410] JIT miscompilation in the JavaScript Engine: JIT component
JIT miscompilation in the JavaScript Engine: JIT component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-1037.
Low [CVE-2026-16409] Invalid pointer in the Security: PSM component
Invalid pointer in the Security: PSM component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-476.
Low [CVE-2026-16408] Integer overflow in the Audio/Video: Playback component
Integer overflow in the Audio/Video: Playback component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-190.
Low [CVE-2026-16407] Mitigation bypass in the DOM: Service Workers component
Mitigation bypass in the DOM: Service Workers component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-807.
Low [CVE-2026-16406] Mitigation bypass in the Networking component
Mitigation bypass in the Networking component. Red Hat rates this low (CVSS 3.4).
Low [CVE-2026-16405] Information disclosure in the Networking: WebSockets component
Information disclosure in the Networking: WebSockets component. Red Hat rates this low (CVSS 3.4). Weakness: CWE-201. Red Hat lists fixing advisory RHSA-2026:47101 with package firefox-0:140.13.0-1.el10_2, firefox-0:140.13.0-1.el8_10, firefox-0:140.13.0-1.el9_8, thunderbird-0:140.13.0-1.el10_2. Affected products named by the advisory: Red Hat Enterprise Linux 1; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Low [CVE-2026-16404] Spoofing issue in Firefox for Android
Spoofing issue in Firefox for Android. Red Hat rates this low (CVSS 3.4). Weakness: CWE-290.
Low [CVE-2026-16403] Spoofing issue in the Address Bar component
Spoofing issue in the Address Bar component. Red Hat rates this low (CVSS 3.4).
Low [CVE-2026-59842] information disclosure via short GSSAPI Curve25519 public key
information disclosure via short GSSAPI Curve25519 public key. Red Hat rates this low (CVSS 3.7). Weakness: CWE-125. Red Hat lists fixing advisory RHSA-2026:42922 with package libssh-main-0.12.1-4.hum1.
Low [CVE-2026-61081] Performance Schema unspecified vulnerability (CPU Jul 2026)
Performance Schema unspecified vulnerability (CPU Jul 2026). Red Hat rates this low (CVSS 2.7). Weakness: CWE-497.