Red Hat Linux Security Advisories & CVEs
4700 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
High [CVE-2025-35973] Privilege escalation in Ring 0 via improper value handling
Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and require no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts. Red Hat is aware of a hardware vulnerability affecting some Intel processors that could allow a local attacker who already has privileged access to escalate privileges by exploiting improper handling of internal processor values during Ring 0 execution. In the most severe case, this could allow a privileged workload running inside a virtual machine to escalate access into the underlying hypervisor. Exploitation requires local access, existing privileged access, and a high degree of attack complexity, including detailed knowledge of the processor's internal behavior.
High [CVE-2026-73078] Arbitrary Code Execution via Crafted Netrw Menu Entries
Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating attacker-controlled directory paths into executed:menu commands. s:NetrwBookmarkMenu(), s:NetrwTgtMenu(), g:netrw_menu_escape, EX_TRLBAR, and netrw#MakeTgt() fail to neutralize the | command separator or single quotes at five construction sites, allowing a crafted path browsed or bookmarked in GUI Vim to execute arbitrary Ex and operating-system commands. This issue is fixed in version 9.2.0840. Browsing or bookmarking a maliciously crafted path in GUI Vim allows attackers to execute arbitrary OS commands as the running user. By crafting a malicious directory path, an attacker could exploit improper neutralization of special characters when the path is browsed or bookmarked, leading to command injection. This issue specifically impacts GUI installations and requires user interaction. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-77. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Affected products named by the advisory: Red Hat package: vim.
High [CVE-2026-73077] Arbitrary Code Execution via Insecure Shell Command Handling
Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.vim filetype plugins pass attacker-controlled Visual-mode selections from K through keywordprg commands without safely separating shell arguments. fnameescape() and PATH_ESC_CHARS do not neutralize shell metacharacters before ShKeywordPrg, ZshKeywordPrg, or GetHelp invokes bash, zsh, or PowerShell, allowing arbitrary operating-system commands to execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0839. A vulnerability in Vim's shell script plugins (sh.vim, zsh.vim, ps1.vim) allows arbitrary code execution if a user selects maliciously crafted text in Visual mode and triggers a keyword lookup, due to improperly escaped shell metacharacters. This does not affect RHEL 8 and older versions. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-78. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:66336, RHSA-2026:66366. Affected products named by the advisory: Red Hat package: vim.
High [CVE-2026-73076] Arbitrary command execution via crafted vimball
Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named. VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimball() later processes the matching record entry, the stored Ex commands, including operating-system commands invoked through:!, execute with the privileges of the user running Vim. This issue is fixed in version 9.2.0847. A vulnerability in Vim allows remote attackers to execute arbitrary commands by crafting a malicious. VimballRecord file that injects OS commands executed when processed by the vimball#RmVimball() function. This is an Important vulnerability in Vim where a crafted vimball can lead to arbitrary command execution. The flaw allows an attacker to embed malicious commands within a `.VimballRecord` file, which are then executed with user privileges during a later, unrelated vimball installation or removal. This extends the impact of processing untrusted vimball files beyond the initial installation. Red Hat severity: Important — CVSS 7.3 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-78. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7.
High [CVE-2026-73072] Heap buffer overflow allows arbitrary code execution
Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_SOFO section causes under-counted mapping lists and attacker-influenced writes beyond a heap allocation. This issue is fixed in version 9.2.0846. A heap buffer overflow in Vim allows a local attacker to cause a denial of service or potentially execute arbitrary code. The flaw is triggered by processing a specially crafted spell file, where the set_sofo() function fails to reset internal data between sections, leading to an out-of-bounds write. Red Hat severity: Important — CVSS 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-787. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat lists Red Hat Hardened Images; Red Hat OpenShift Container Platform 4 as not affected. Red Hat fixing advisory: RHSA-2026:66336, RHSA-2026:66348, RHSA-2026:66366. Affected products named by the advisory: Red Hat package: vim.
High [CVE-2026-14380 +1] Incomplete fix for CVE-2026-14380 DBI: Arbitrary code execution via caller-influenced Profile attribute
A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mitigation please reffer to the original. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-94. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9. Red Hat fixing advisory: RHSA-2026:65887, RHSA-2026:66179. Affected products named by the advisory: Red Hat package: perl-dbi.
High [CVE-2026-73066] Heap out-of-bounds write via crafted.traineddata
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted.traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution output-channel count, undersizing the forward-pass output buffer while writes use the unwrapped element count and causing a heap out-of-bounds write during OCR recognition. This issue is fixed in version 5.5.3. A remote attacker could exploit this by providing a specially crafted.traineddata LSTM model component. This vulnerability could result in a denial of service or potentially arbitrary code execution. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; and 9 more.
High [CVE-2026-72746] Authentication bypass in RDSTLS handshake via PDU-type confusion
FreeRDP before 3.30.0 contains a server-side authentication bypass in the RDSTLS handshake. When a server is configured with RdstlsSecurity = TRUE, the handshake dispatches inbound PDUs based solely on the attacker-supplied wire pduType without verifying that the received PDU is the one required at the current step. Because the rdpRdstls object is calloc-zeroed, its resultCode defaults to 0 (RDSTLS_RESULT_SUCCESS). An unauthenticated remote client can send a Capabilities PDU instead of the required Authentication Request PDU; rdstls_process_capabilities() returns success without ever setting resultCode, so the server responds with an AUTHRSP carrying resultCode SUCCESS and treats the session as authenticated without evaluating any password, redirection GUID, or auto-reconnect cookie. This affects the released FreeRDP 3.x series (e.g., 3.27.1) and master HEAD; at the time of the advisory no patched version was available. By sending a Capabilities PDU instead of the expected Authentication Request PDU, the server incorrectly processes the request, leading to a successful authentication without validating any credentials. This allows the attacker to gain unauthorized access to a session. This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-73241.
High [CVE-2026-50236] Authenticated SSRF with full response reflection and path neutralization via Dev Console webhook helpers in OpenShift Console
An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without validation, with path neutralization enabling arbitrary endpoint targeting and full response reflection from the console pod's privileged network position. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L). Weakness: CWE-918. Affected Red Hat products: Red Hat OpenShift Container Platform 4.14; Red Hat OpenShift Container Platform 4.15; Red Hat OpenShift Container Platform 4.16; Red Hat OpenShift Container Platform 4.17; Red Hat OpenShift Container Platform 4.18; Red Hat OpenShift Container Platform 4.19; Red Hat OpenShift Container Platform 4.2; Red Hat OpenShift Container Platform 4.21; Red Hat OpenShift Container Platform 4.22. Red Hat fixing advisory: RHSA-2026:56789, RHSA-2026:56912, RHSA-2026:56854, RHSA-2026:60023, RHSA-2026:54545, RHSA-2026:54555, RHSA-2026:54583, RHSA-2026:54602, RHSA-2026:54770.
High [CVE-2026-50237] Namespace tenant SSRF with egress bypass, catalog poisoning, and admin-mediated supply chain escalation via ProjectHelmChartRepository in OpenShift Console
A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelmChartRepository with an arbitrary URL that the console pod fetches server-side, bypassing tenant egress restrictions. Combined with catalog metadata poisoning and admin-mediated chart installation, this enables privilege escalation. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L). Weakness: CWE-918. Affected Red Hat products: Red Hat OpenShift Container Platform 4.12; Red Hat OpenShift Container Platform 4.13; Red Hat OpenShift Container Platform 4.14; Red Hat OpenShift Container Platform 4.15; Red Hat OpenShift Container Platform 4.16; Red Hat OpenShift Container Platform 4.17; Red Hat OpenShift Container Platform 4.18; Red Hat OpenShift Container Platform 4.19; Red Hat OpenShift Container Platform 4.2; Red Hat OpenShift Container Platform 4.21; Red Hat OpenShift Container Platform 4.22. Red Hat fixing advisory: RHSA-2026:54206, RHSA-2026:54188, RHSA-2026:56789, RHSA-2026:56912, RHSA-2026:56854, RHSA-2026:60023, RHSA-2026:54545, RHSA-2026:54555, RHSA-2026:54583, RHSA-2026:54602, RHSA-2026:54770.
High [CVE-2026-72552] Server-Side Request Forgery allows information disclosure and internal network scanning
A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the server issue HTTP requests to arbitrary internal or external hosts via the metatags edge endpoint. The endpoint fetches any caller-supplied URL without applying a denylist or requiring authentication. An attacker can use this to scan internal services or exfiltrate data from cloud metadata endpoints. A flaw was found in Dub. This can be exploited via the `metatags` edge endpoint, which processes caller-supplied URLs without proper validation or authentication. Successful exploitation could lead to information disclosure, such as scanning internal services or exfiltrating data from cloud metadata endpoints. An unauthenticated remote attacker can supply arbitrary HTTP/HTTPS URLs to the endpoint, which fetches caller-provided addresses without enforcing IP denylists, domain egress controls, or authentication requirements. Consequently, the server executes arbitrary outbound network requests on behalf of the attacker, enabling internal network port scanning and exposure of local metadata endpoints or internal web services, posing an Important impact to confidentiality. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-918.
High [CVE-2026-71217] iperf3 server accepts unbounded peer-controlled JSON parameters enabling remote denial of service via resource exhaustion
A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameters, such as `parallel` and `len`, which are not properly validated by the server. This improper input validation can lead to excessive stream and thread creation, as well as large buffer allocations, causing resource exhaustion. Consequently, this can result in a Denial of Service (DoS) on the affected iperf3 server. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-20. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Enterprise Linux 7. Red Hat fixing advisory: RHSA-2026:61680, RHSA-2026:61257, RHSA-2026:61389. Affected products named by the advisory: Red Hat package: iperf3.
High [CVE-2026-15567] Pre-auth denial of service on the IIOP listener
A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that size. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Affected Red Hat products: Red Hat JBoss Enterprise Application Platform 7.4.25; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7. Red Hat lists Red Hat JBoss Enterprise Application Platform Expansion Pack as not affected. Will not fix / out of support: Red Hat Fuse 7; Red Hat Single Sign-On 7. Red Hat fixing advisory: RHSA-2026:53806, RHSA-2026:53644, RHSA-2026:53645, RHSA-2026:53646, RHSA-2026:70230, RHSA-2026:70228, RHSA-2026:70229.
High [CVE-2026-15565] Pre-Auth DoS on websocket endpoint with @ServerEndpoint class with any @OnMessage method
A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service attack without authentication and using only a standard WebSocket handshake. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat JBoss Enterprise Application Platform 7.4.25; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat build of Apache Camel for Spring Boot 4; Red Hat Data Grid 8; Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform 7; Red Hat Single Sign-On 7. Red Hat lists Red Hat JBoss Enterprise Application Platform Expansion Pack as not affected. Will not fix / out of support: Red Hat Data Grid 8; Red Hat Fuse 7; Red Hat Single Sign-On 7. Red Hat fixing advisory: RHSA-2026:53806, RHSA-2026:53644, RHSA-2026:53645, RHSA-2026:53646, RHSA-2026:70230, RHSA-2026:70228, RHSA-2026:70229.
High [CVE-2026-15563] Missing authentication on EAP's IIOP NameService leads to MITM or DoS
A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations. Red Hat severity: Important — CVSS 7.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-306. Affected Red Hat products: Red Hat JBoss Enterprise Application Platform 7.4.25; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9; Red Hat JBoss Enterprise Application Platform 8.1; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat Single Sign-On 7.6.13; Red Hat Single Sign-On 7.6 for RHEL 7; Red Hat Single Sign-On 7.6 for RHEL 8; Red Hat Single Sign-On 7.6 for RHEL 9; RHEL-8 based Middleware Containers; Red Hat JBoss Enterprise Application Platform 7. Red Hat lists Red Hat Fuse 7; Red Hat JBoss Enterprise Application Platform Expansion Pack as not affected.
High [CVE-2026-15562] integer overflow in MessageReader leads to pre-authentication denial of service
A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach:8080 (or:9990, or:4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to denial of service. This is an Important denial of service vulnerability in jboss-remoting affecting Red Hat JBoss Enterprise Application Platform. A remote, unauthenticated attacker can exploit an integer overflow in the MessageReader by completing a jboss-remoting handshake on exposed ports, leading to a severe degradation of server performance and potential resource exhaustion. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat JBoss Enterprise Application Platform 7.4.25; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat JBoss Enterprise Application Platform 7. Red Hat lists Red Hat JBoss Enterprise Application Platform Expansion Pack as not affected.
High [CVE-2026-15561] OOM via missing limits in chunked trailer in EAP's Undertow
A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the listener, and achieving Denial of Service. Red Hat severity: Important — CVSS 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-770. Affected Red Hat products: Red Hat JBoss Enterprise Application Platform 7.4.25; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat JBoss Enterprise Application Platform 7. Red Hat lists Red Hat JBoss Enterprise Application Platform Expansion Pack as not affected. Red Hat fixing advisory: RHSA-2026:53806, RHSA-2026:53644, RHSA-2026:53645, RHSA-2026:53646, RHSA-2026:70230, RHSA-2026:70228, RHSA-2026:70229.
High [CVE-2026-15560] unauthed class loading via IIOP in EAP
when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on:3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-829. Affected Red Hat products: Red Hat JBoss Enterprise Application Platform 7.4.25; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9; Red Hat JBoss Enterprise Application Platform 8.1; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat JBoss Enterprise Application Platform 7. Red Hat lists Red Hat JBoss Enterprise Application Platform Expansion Pack as not affected. Red Hat fixing advisory: RHSA-2026:53806, RHSA-2026:53644, RHSA-2026:53645, RHSA-2026:53646, RHSA-2026:70277, RHSA-2026:70230, RHSA-2026:70228, RHSA-2026:70229.
High [CVE-2026-15556] picketlink SAML 2.0 auth bypass via missing assertions
A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the protected application. Red Hat JBoss EAP 8.x is not affected. The vulnerable components (`picketlink-federation`, `picketlink-common`) are not shipped in EAP 8.x. The `org/picketlink/` module path does not exist. The only PicketLink-related artifact in EAP 8.1 is `wildfly-picketlink-8.1.1.GA-redhat-00012.jar` — a WildFly subsystem extension that provides the `migrate` CLI operation for EAP 7→8 upgrades. This JAR contains no SAML processing code, no signature validation logic, and has no module dependency on `org.picketlink.federation`. The PicketLink SAML SP code path is entirely absent from EAP 8.x. Red Hat severity: Important — CVSS 8.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). Weakness: CWE-347. Affected Red Hat products: Red Hat JBoss Enterprise Application Platform 7.4.25; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9; Red Hat JBoss Enterprise Application Platform 7. Red Hat fixing advisory: RHSA-2026:53806, RHSA-2026:53644, RHSA-2026:53645, RHSA-2026:53646.
High [CVE-2026-15555] wildfly-clustering-infinispan-marshalling: Jboss Deserialization RCE via Unfiltered River Unmarshaller
A flaw was found in JBoss marshalling. Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). Weakness: CWE-502. Affected Red Hat products: Red Hat JBoss Enterprise Application Platform 7.4.25; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 8; Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 9; Red Hat JBoss Enterprise Application Platform 8.1; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 10; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8; Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9; Red Hat JBoss Enterprise Application Platform 7; Red Hat JBoss Enterprise Application Platform 8; Red Hat JBoss Enterprise Application Platform Expansion Pack. Red Hat fixing advisory: RHSA-2026:53806, RHSA-2026:53644, RHSA-2026:53645, RHSA-2026:53646, RHSA-2026:70277, RHSA-2026:70230, RHSA-2026:70228, RHSA-2026:70229.