Skip to content
VulniPulse

Red Hat Linux Security Advisories & CVEs

408 advisories tracked · Red Hat Security Data API · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Security advisories for your Red Hat release

Pick your distribution release to see every advisory issued for it and its severity mix. Fixes ship as errata — keep the system patched. This is the release's advisory history, not a per-package scan.

Official source

Red Hat Security Data API

Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.

Latest Red Hat advisories

Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-70496] operator ClusterRole is cluster-admin equivalent via impersonate, RBAC write, CSR approve, and ManifestWork

operator ClusterRole is cluster-admin equivalent via impersonate, RBAC write, CSR approve, and ManifestWork. Red Hat rates this important (CVSS 9.9). Weakness: CWE-250. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-70496
Unclassified
Aug 19, 2026
Critical9.1Vendor: HighRed Hat Updated

Critical [CVE-2026-71470] Search CR imageOverride/arguments/envVar flow unsanitized into pods running impersonating SA

A flaw was found in the search-v2-operator. This vulnerability allows a privileged user, specifically a Custom Resource (CR) editor, to manipulate Search CR fields such as imageOverride, arguments, and environment variables without proper validation. By exploiting this, an attacker can mount arbitrary secrets into a search container's environment or replace the container image with an attacker-controlled one. This leads to privilege escalation and can result in a full cluster compromise due to the ServiceAccount's extensive impersonation permissions. This is an Important vulnerability in Red Hat Advanced Cluster Management for Kubernetes. Exploitation requires an already-privileged CR editor, which is why this does not meet the bar for Critical under the unauthenticated-RCE standard. Red Hat severity: Important — CVSS 9.1 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). Weakness: CWE-913. Red Hat does not currently list a fixing RHSA for this CVE. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-71470
Unclassified
Aug 19, 2026
Critical9.3Vendor: HighRed Hat

Critical [CVE-2026-66794] unauthenticated SSRF to arbitrary managed-cluster services via public Route

A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker, who can access the user-facing route, to bypass authentication and authorization checks. By manipulating URL path segments, the attacker can proxy requests to arbitrary services across any managed cluster. This enables unauthorized access to internal services that would otherwise be protected, potentially leading to information disclosure or further compromise of the cluster environment. Red Hat severity: Important — CVSS 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N). Weakness: CWE-918. Affected Red Hat products: Multicluster Engine for Kubernetes. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-66794
Unclassified
Aug 19, 2026
Critical9.0Vendor: HighRed Hat Updated

Critical [CVE-2026-76044] Arbitrary code execution due to a race condition in USB

Arbitrary code execution due to a race condition in USB. Red Hat rates this important (CVSS 9). Weakness: CWE-368.

CVE-2026-76044
Unclassified
Aug 18, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-66780] flat broker trust model grants every spoke full CRUD on all endpoints, secrets, and endpointslices in broker namespace

flat broker trust model grants every spoke full CRUD on all endpoints, secrets, and endpointslices in broker namespace. Red Hat rates this important (CVSS 9.9). Weakness: CWE-284. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-66780
Unclassified
Aug 18, 2026
Critical9.1Red Hat Updated

Critical [CVE-2026-18963] Unauthenticated account takeover via reset-credentials flow bypass

Unauthenticated account takeover via reset-credentials flow bypass. Red Hat rates this critical (CVSS 9.1). Weakness: CWE-640. Red Hat lists fixing advisory RHSA-2026:56524 with package rhbk/keycloak-rhel9:26.6-12, rhbk-keycloak-rhel9/rhbk-keycloak-rhel9, keycloak-services, rhbk-openshift-rhel9/rhbk-openshift-rhel9. Affected products named by the advisory: Red Hat build of Keycloak 26.4; Red Hat build of Keycloak 26.6; Red Hat JBoss Enterprise Application Platform Expansion Pack.

CVE-2026-18963
Unclassified
Aug 18, 2026
Critical9.6Red Hat

Critical [CVE-2026-12564] Automation-controller: automation-controller: kubernetes service account token exfiltration via hashicorp vault credential ssrf

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. An authenticated attacker with credential-creation privileges can exfiltrate the service account token, gaining Kubernetes API access to the control plane namespaces with full pod CRUD and secret read permissions, including database credentials and the Django SECRET_KEY. The vulnerability is particularly impactful in AAP Cloud (managed service) environments where the Kubernetes control plane is managed by Red Hat and tenant isolation is a security boundary. On-premise deployments are also affected, though the impact is lower since the administrator already has access to the infrastructure. The vulnerable code path exists in all AAP versions that ship the hashivault credential plugin with kubernetes_role authentication support. Red Hat severity: Critical — CVSS 9.6 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N). Weakness: CWE-918. Affected Red Hat products: Red Hat Ansible Automation Platform 2. Red Hat does not currently list a fixing RHSA for this CVE.

CVE-2026-12564
Unclassified
Aug 18, 2026
Critical9.1Vendor: HighRed Hat Updated

Critical [CVE-2026-66795] CSR auto-approver does not validate certificate Subject, signerName, or requester identity

CSR auto-approver does not validate certificate Subject, signerName, or requester identity. Red Hat rates this important (CVSS 9.1). Weakness: CWE-295. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-66795
Unclassified
Aug 17, 2026
Critical9.1Vendor: HighRed Hat Updated

Critical [CVE-2026-71472] Shell-command and SQL injection in postgresql-start.sh via CR-supplied WORK_MEM

Shell-command and SQL injection in postgresql-start.sh via CR-supplied WORK_MEM. Red Hat rates this important (CVSS 9.1). Weakness: CWE-78. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-71472
Unclassified
Aug 17, 2026
Critical9.9Vendor: HighRed Hat Updated

Critical [CVE-2026-66792] IsClusterAdmin trusts user-settable annotations on managed clusters

IsClusterAdmin() trusts user-settable annotations on managed clusters. Red Hat rates this important (CVSS 9.9). Weakness: CWE-863. Affected products named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2; Red Hat OpenShift Container Platform 4.

CVE-2026-66792
Unclassified
Aug 17, 2026
Critical9.0Vendor: HighRed Hat

Critical [CVE-2026-71471] Hub Search CR Collector.ImageOverride propagated to every spoke as arbitrary container image

Hub Search CR Collector. ImageOverride propagated to every spoke as arbitrary container image. Red Hat rates this important (CVSS 9). Weakness: CWE-829. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-71471
Unclassified
Aug 12, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-72508] hub and spoke ServiceAccounts bound to wildcard RBAC (*/*/*)

hub and spoke ServiceAccounts bound to wildcard RBAC (*/*/*). Red Hat rates this important (CVSS 9.9). Weakness: CWE-250. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-72508
Unclassified
Aug 12, 2026
Critical9.6Vendor: HighRed Hat

Critical [CVE-2026-70398] GitOpsCluster.spec.argoServer.argoNamespace writes spoke bearer tokens to attacker-chosen namespace

GitOpsCluster.spec.argoServer.argoNamespace writes spoke bearer tokens to attacker-chosen namespace. Red Hat rates this important (CVSS 9.6). Weakness: CWE-441. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-70398
Unclassified
Aug 12, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-72526] pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation

pull-model propagation allows hub tenant to target arbitrary spoke cluster via unvalidated ocm-managed-cluster annotation. Red Hat rates this important (CVSS 9.9). Weakness: CWE-441. Affected product named by the advisory: Red Hat Advanced Cluster Management for Kubernetes 2.

CVE-2026-72526
Unclassified
Aug 12, 2026
Critical9.9Red Hat

Critical [CVE-2026-73213] Server-Side Request Forgery via incorrect IPv6 comparison

Server-Side Request Forgery via incorrect IPv6 comparison. Red Hat rates this critical (CVSS 9.9). Weakness: CWE-918.

CVE-2026-73213
Unclassified
Aug 11, 2026
Critical9.8Red Hat

Critical [CVE-2026-10579] auth bypass in Picketlink SAML unsolicited-response

auth bypass in Picketlink SAML unsolicited-response. Red Hat rates this critical (CVSS 9.8). Red Hat lists fixing advisory RHSA-2026:53806 with package eap7-ironjacamar-0:1.5.26-2.Final_redhat_00001.1.el7eap, eap7-undertow-0:2.2.40-2.SP3_redhat_00001.1.el7eap, eap7-wildfly-0:7.4.25-2.GA_redhat_00001.1.el7eap, eap7-netty-0:4.1.135-1.Final_redhat_00001.1.el7eap. Affected product named by the advisory: Red Hat JBoss Enterprise Application Platform 7.

CVE-2026-10579
Unclassified
Aug 11, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-73268] spec.install.overrideJob allows arbitrary Job spec injection

spec.install.overrideJob allows arbitrary Job spec injection. Red Hat rates this important (CVSS 9.9). Weakness: CWE-94. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-73268
Unclassified
Aug 11, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-73269] tenant-controllable trigger creates ClusterRoleBinding granting cluster-wide secrets access to namespace-local SA

tenant-controllable trigger creates ClusterRoleBinding granting cluster-wide secrets access to namespace-local SA. Red Hat rates this important (CVSS 9.9). Weakness: CWE-269. Affected product named by the advisory: Multicluster Engine for Kubernetes.

CVE-2026-73269
Unclassified
Aug 11, 2026
Critical9.9Red Hat Updated

Critical [CVE-2026-18948] Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server

Unsafe dill deserialization of registry-stored UDFs — RCE on feature server and registry server. Red Hat rates this critical (CVSS 9.9). Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-feature-server-rhel9:1786110051, rhoai/odh-feature-server-rhel9:1786110033, rhoai/odh-feature-server-rhel9:1786107278. Affected products named by the advisory: Red Hat OpenShift AI 2.25; Red Hat OpenShift AI 3.3; Red Hat OpenShift AI 3.4.

CVE-2026-18948
Unclassified
Aug 10, 2026
Critical9.9Vendor: HighRed Hat

Critical [CVE-2026-14450] Privilege escalation via forged HTTP headers due to missing authentication

Privilege escalation via forged HTTP headers due to missing authentication. Red Hat rates this important (CVSS 9.9). Weakness: CWE-290. Red Hat lists fixing advisory RHSA-2026:53262 with package rhoai/odh-maas-api-rhel9:1785850409. Affected products named by the advisory: Red Hat OpenShift AI (RHOAI); Red Hat OpenShift AI 3.4.

CVE-2026-14450
Unclassified
Aug 10, 2026

← All vendors