Red Hat Linux Security Advisories & CVEs
514 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Security advisories for your Red Hat release
Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.
Official source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat advisories
Critical [CVE-2026-86345] StartTLS plaintext-buffer retention allows on-path attacker to forge an LDAP client's authentication result
StartTLS plaintext-buffer retention allows on-path attacker to forge an LDAP client's authentication result. Red Hat rates this moderate (CVSS 9). Weakness: CWE-923. Affected products named by the advisory: Red Hat Directory Server 11; Red Hat Directory Server 12; Red Hat Directory Server 13; Red Hat Enterprise Linux 10; and 2 more. Affected products named by the advisory: Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Critical [CVE-2026-96658] Safemode Bypass leading to RCE
Safemode Bypass leading to RCE. Red Hat rates this critical (CVSS 9.9). Red Hat lists fixing advisory RHSA-2026:74503 with package python-sqlparse-0:0.6.0-1.el9pc, python-gitpython-0:3.1.62-1.el9pc, python-dynaconf-0:3.2.13-1.el9pc, python-lxml-0:5.3.1-2.el9pc. Affected products named by the advisory: Red Hat Satellite 6.16 for RHEL 8; Red Hat Satellite 6.16 for RHEL 9; Red Hat Satellite 6.17 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9; and 1 more. Affected products named by the advisory: Red Hat Satellite 6.19 for RHEL 9.
Critical [CVE-2026-96659] Excessive Permissions for Viewer Role on Preview
Excessive Permissions for Viewer Role on Preview. Red Hat rates this important (CVSS 9.1). Weakness: CWE-267. Red Hat lists fixing advisory RHSA-2026:74503 with package python-sqlparse-0:0.6.0-1.el9pc, python-gitpython-0:3.1.62-1.el9pc, python-dynaconf-0:3.2.13-1.el9pc, python-lxml-0:5.3.1-2.el9pc. Affected products named by the advisory: Red Hat Satellite 6.16 for RHEL 8; Red Hat Satellite 6.16 for RHEL 9; Red Hat Satellite 6.17 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9; and 1 more. Affected products named by the advisory: Red Hat Satellite 6.19 for RHEL 9.
Critical [CVE-2026-102331] arbitrary code execution via buffer overflow in ANGLE
arbitrary code execution via buffer overflow in ANGLE. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Critical [CVE-2026-95331] Out of bounds write in ANGLE
Out of bounds write in ANGLE. Red Hat rates this moderate (CVSS 9.6). Weakness: CWE-787. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Critical [CVE-2026-95274] Improper output encoding in DevTools
Improper output encoding in DevTools. Red Hat rates this important (CVSS 9.6). Weakness: CWE-116.
Critical [CVE-2026-95310] Use after free in AdFilter
Use after free in AdFilter. Red Hat rates this important (CVSS 9.6). Weakness: CWE-416.
Critical [CVE-2026-95329] Out of bounds write in WebGL
Out of bounds write in WebGL. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787.
Critical [CVE-2026-95284] Buffer overflow in ANGLE
Buffer overflow in ANGLE. Red Hat rates this important (CVSS 9.6). Weakness: CWE-122. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 3 more. Affected products named by the advisory: Red Hat package: webkitgtk3; Red Hat package: webkitgtk4; Red Hat package: webkit2gtk3.
Critical [CVE-2026-95357] Out of bounds write in GPU
Out of bounds write in GPU. Red Hat rates this important (CVSS 9.6). Weakness: CWE-787.
Critical [CVE-2026-100811] Sandbox escape via use-after-free in DOM component
Sandbox escape via use-after-free in DOM component. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: firefox.
Critical [CVE-2026-100786] Sandbox escape via use-after-free in Graphics component
Sandbox escape via use-after-free in Graphics component. Red Hat rates this important (CVSS 9.6). Weakness: CWE-825. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: firefox.
Critical [CVE-2026-84719] WorkflowJobTemplate /copy/ deep-copy sanitizer omits instance_groups authorization (InstanceGroup use_role bypass to control-plane)
WorkflowJobTemplate /copy/ deep-copy sanitizer omits instance_groups authorization (InstanceGroup use_role bypass to control-plane). Red Hat rates this critical (CVSS 9.9). Weakness: CWE-862. Red Hat lists fixing advisory RHSA-2026:71177 with package automation-controller-0:4.5.36-1.el8ap, automation-controller-0:4.5.36-1.el9ap, ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.4 for RHEL 8; Red Hat Ansible Automation Platform 2.4 for RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; and 2 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Critical [CVE-2026-75884] Privilege escalation to OpenShift namespace via pod_spec_override injection in container groups
Privilege escalation to OpenShift namespace via pod_spec_override injection in container groups. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-184. Red Hat lists fixing advisory RHSA-2026:71177 with package automation-controller-0:4.5.36-1.el8ap, automation-controller-0:4.5.36-1.el9ap, ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.4 for RHEL 8; Red Hat Ansible Automation Platform 2.4 for RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; and 2 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Critical [CVE-2026-84502] Project scm_url argument injection into `git ls-remote --upload-pack` yields RCE on the controller-task control-plane pod
Project scm_url argument injection into `git ls-remote --upload-pack` yields RCE on the controller-task control-plane pod. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-88. Red Hat lists fixing advisory RHSA-2026:71177 with package automation-controller-0:4.5.36-1.el8ap, automation-controller-0:4.5.36-1.el9ap, ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.4 for RHEL 8; Red Hat Ansible Automation Platform 2.4 for RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; and 2 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Critical [CVE-2026-84474] view_jobtemplate to execute privilege escalation via host_config_key exposure and X-Forwarded-For spoofing of provisioning-callback host match
view_jobtemplate to execute privilege escalation via host_config_key exposure and X-Forwarded-For spoofing of provisioning-callback host match. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-807. Red Hat lists fixing advisory RHSA-2026:71177 with package automation-controller-0:4.5.36-1.el8ap, automation-controller-0:4.5.36-1.el9ap, ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.4 for RHEL 8; Red Hat Ansible Automation Platform 2.4 for RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; and 2 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Critical [CVE-2026-84638] instance group attachment to schedules and workflow job template nodes checks only read permission, allowing use of restricted (controlplane / other-tenant) instance groups and privilege escalation…
instance group attachment to schedules and workflow job template nodes checks only read permission, allowing use of restricted (controlplane / other-tenant) instance groups and privilege escalation to control-plane code execution. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:71177 with package automation-controller-0:4.5.36-1.el8ap, automation-controller-0:4.5.36-1.el9ap, ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.4 for RHEL 8; Red Hat Ansible Automation Platform 2.4 for RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; and 2 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Critical [CVE-2026-84684] constructed inventory input inventory attachment checks only read permission on the source inventory, allowing a read-only user to clone another tenant's hosts and secrets and run ad hoc commands a…
constructed inventory input inventory attachment checks only read permission on the source inventory, allowing a read-only user to clone another tenant's hosts and secrets and run ad hoc commands against them. Red Hat rates this critical (CVSS 9.6). Weakness: CWE-863. Red Hat lists fixing advisory RHSA-2026:71177 with package automation-controller-0:4.5.36-1.el8ap, automation-controller-0:4.5.36-1.el9ap, ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.4 for RHEL 8; Red Hat Ansible Automation Platform 2.4 for RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; and 2 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Critical [CVE-2026-84711] Project scm_branch/scm_refspec argument injection into git during project sync allows arbitrary file read on the sync host (control-plane ServiceAccount token, SECRET_KEY, and DB credentials on con…
Project scm_branch/scm_refspec argument injection into git during project sync allows arbitrary file read on the sync host (control-plane ServiceAccount token, SECRET_KEY, and DB credentials on control-plane deployments) leading to full AAP and Kubernetes-namespace compromise. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-88. Red Hat lists fixing advisory RHSA-2026:71177 with package automation-controller-0:4.5.36-1.el8ap, automation-controller-0:4.5.36-1.el9ap, ansible-automation-platform-27/controller-rhel9:1789580684, automation-controller-0:4.7.17-1.el9ap. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.4 for RHEL 8; Red Hat Ansible Automation Platform 2.4 for RHEL 9; Red Hat Ansible Automation Platform 2.5 for RHEL 8; Red Hat Ansible Automation Platform 2.5 for RHEL 9; and 2 more. Affected products named by the advisory: Red Hat Ansible Automation Platform 2.6 for RHEL 9; Red Hat Ansible Automation Platform 2.7.
Critical [CVE-2026-94084] use-after-free in HTTP/2 response header inspection
use-after-free in HTTP/2 response header inspection. Red Hat rates this critical (CVSS 9.8). Weakness: CWE-416.