Red Hat Linux OS and other open source products
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Red Hat product.
RSS Feeds for Red Hat security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Red Hat products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Red Hat Sorted by Most Security Vulnerabilities since 2018
Red Hat Enterprise Linux Server1534 vulnerabilities
RedHat Enterprise Linux (RHEL) Server. Includes software bundeled with RHEL server.
Red Hat Enterprise Linux Workstation1504 vulnerabilities
RedHat Enterprise Linux (RHEL) Workstation. Includes software bundled with RHEL Workstation.
Red Hat Enterprise Linux Desktop1493 vulnerabilities
RedHat Enterprise Linux (RHEL) Desktop. Includes software bundled with RHEL desktop
Recent Red Hat Security Advisories
| Advisory | Title | Published |
|---|---|---|
| RHSA-2026:66545 | (RHSA-2026:66545) Important: Red Hat AMQ Broker 7.13.6 release and security update | September 10, 2026 |
| RHSA-2026:66542 | (RHSA-2026:66542) Important: nginx security update | September 10, 2026 |
| RHSA-2026:66488 | (RHSA-2026:66488) Important: Red Hat AMQ Broker 7.14.1 release and security update | September 10, 2026 |
| RHSA-2026:66460 | (RHSA-2026:66460) Moderate: gstreamer1-plugins-base security update | September 10, 2026 |
| RHSA-2026:66459 | (RHSA-2026:66459) Important: grafana-pcp security update | September 10, 2026 |
| RHSA-2026:66432 | (RHSA-2026:66432) Important: osbuild-composer security update | September 10, 2026 |
| RHSA-2026:66410 | (RHSA-2026:66410) Important: openssh security update | September 10, 2026 |
| RHSA-2026:66407 | (RHSA-2026:66407) Important: gstreamer1-plugins-bad-free security update | September 10, 2026 |
| RHSA-2026:66406 | (RHSA-2026:66406) Important: gstreamer1-plugins-bad-free security update | September 10, 2026 |
| RHSA-2026:66405 | (RHSA-2026:66405) Important: rsyslog security update | September 10, 2026 |
By the Year
In 2026 there have been 3179 vulnerabilities in Red Hat with an average score of 7.2 out of ten. Last year, in 2025 Red Hat had 1178 security vulnerabilities published. That is, 2001 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.35.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 3179 | 7.21 |
| 2025 | 1178 | 6.86 |
| 2024 | 1694 | 6.82 |
| 2023 | 1207 | 6.74 |
| 2022 | 1362 | 6.96 |
| 2021 | 1123 | 6.61 |
| 2020 | 664 | 6.39 |
| 2019 | 772 | 6.98 |
| 2018 | 760 | 7.16 |
It may take a day or so for new Red Hat vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Red Hat Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-89329 | Sep 11, 2026 |
Red Hat multipathd IPC DoS via blocked listener threadA flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity. |
|
| CVE-2026-18495 | Sep 11, 2026 |
libtiff tiff2pdf Heap-BUF Overflow via Truncated StripByteCountsA flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption. |
And others... |
| CVE-2026-89298 | Sep 11, 2026 |
Keycloak DCR Service Leak: Admin Role Reveals Client SecretA flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution. The issue occurs when a user with the view-clients role accesses the client registration endpoint to retrieve client details. Due to a failure to mask sensitive information, the service returns the client's confidential secret in cleartext. This could allow a read-only administrator to obtain full access to the affected client's account and potentially escalate their privileges within the realm. |
|
| CVE-2026-77159 | Sep 11, 2026 |
Privilege Escalation via Symlink Chown in libvirt qemuTPMEmulatorPrepareHostA symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can replace the logfile with a symlink, causing libvirtd (running as root) to transfer ownership of an arbitrary file to the swtpm user. |
|
| CVE-2026-89060 | Sep 11, 2026 |
CVE-2026-89060: multicluster-observability-addon Namespace EscalationA cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed clusters ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster. |
|
| CVE-2026-88914 | Sep 11, 2026 |
GStreamer gst-plugins-good isomp4 Integer Overflow in Closed-Caption ParserA flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes, which is then included in the downstream caption output. An attacker could exploit this by tricking a user into opening a malicious media file, potentially resulting in disclosure of adjacent heap memory or application crash. |
|
| CVE-2026-88924 | Sep 10, 2026 |
Local Privilege Escalation via TOCTOU in gvfsd-admin (Red Hat)A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root. |
|
| CVE-2026-88859 | Sep 10, 2026 |
Evolution JS Execution via Spoofed vCard Control in HTML EmailA flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler incorrectly assigns an attacker-controlled JavaScript URL to an iframe's source. This action leads to arbitrary JavaScript execution within the mail-viewing context, effectively bypassing the security measures designed to prevent script execution in email content. |
|
| CVE-2026-84828 | Sep 10, 2026 |
PCS: Local File Disclosure via pcs host auth --tokenA flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the files are shorter than 256 bytes. The file contents are read with root privileges by the pcsd daemon and can be exfiltrated by the attacker through subsequent cluster node communication. This allows disclosure of sensitive data such as API keys, tokens, or configuration secrets that would otherwise be inaccessible to the attacker. |
And others... |
| CVE-2026-88265 | Sep 10, 2026 |
CVE-2026-88265: crun 1.29.1 and below pivot_root stdio symlink issueA flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet. |
|
| CVE-2026-88264 | Sep 10, 2026 |
crun 1.29.1: /dev Console Redirect via Terminal Setup Insecure Bind-MountA flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet. |
|
| CVE-2026-84042 | Sep 10, 2026 |
crun 1.29+ Priv Esc via PassNet (libkrun)A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The issue is a regression in crun 1.29. It affects crun >= 1.29 |
|
| CVE-2026-44950 | Sep 10, 2026 |
Heap buffer overflow in libXfont2 fs_read_glyphs()fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination cursor has exceeded the allocation. A malicious font server can send overlapping source offsets -- for example 1000 glyphs each referencing {position:0, length:64} with nbytes=64. Each individual source range passes the existing validation, but the cumulative writes total 64000 bytes into a 64-byte destination buffer. This is a heap buffer overflow with attacker-controlled content. |
|
| CVE-2026-59679 | Sep 10, 2026 |
OOB Heap Read in libXfont2 query glyphs (CVE-2026-59679)fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked. A malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. This causes attacker-controlled out-of-bounds heap read and writes. |
|
| CVE-2026-88770 | Sep 10, 2026 |
Keycloak Device Auth Grant Brute-Force Bypass for Locked AccountsA flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue occurs because the token redemption process fails to check if a user account is currently locked due to brute-force protection. If an attacker has an active session for a locked account, they can complete the device login process and receive new security tokens. This allows the attacker to maintain access to the account even when it should be temporarily disabled to prevent unauthorized entry. |
|
| CVE-2026-88763 | Sep 10, 2026 |
SkupperRouter AMQP Parser Recursion DoS (Stack Overflow)A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message using its AMQP field parser. Due to a lack of bounds on recursion during parsing, the router can run out of stack memory and crash, leading to a denial of service for the interconnected network. |
|
| CVE-2026-49362 | Sep 10, 2026 |
Apache Artemis/ActiveMQ Artemis CORE Protocol Durable Queue RCE 2.50.0-2.57.0An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. |
|
| CVE-2026-49363 | Sep 10, 2026 |
Apache Artemis CORE Protocol Topology Disclosure 2.50.0-2.57.0An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. |
|
| CVE-2026-49364 | Sep 10, 2026 |
Apache Artemis: Unauth Capture via Cluster Handshake (2.50-2.56, 1.0-2.44)An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. |
|
| CVE-2026-57822 | Sep 10, 2026 |
Apache Artemis 2.44-2.57 OSS: Java Deserialization DOS in Management RequestsWhen the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that the broker will not utilise. The permitted types allow to craft a payload causing excessive computation and pinning the processing thread, leading to denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.3.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. |
|
| CVE-2026-57967 | Sep 10, 2026 |
Apache Artemis SESSION_REATTACH RCE 2.50.0-2.56.0An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. |
|
| CVE-2026-67593 | Sep 10, 2026 |
Artemis OpenWire RemoveSubscriptionInfo Queue Deletion pre-auth (v2.50.02.56.0)A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. |
|
| CVE-2026-18147 | Sep 09, 2026 |
FreeIPA Web UI DOM XSS in Password ResetA flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inject and execute arbitrary JavaScript code. This allows the attacker to perform actions within the victim's authenticated session, potentially leading to full administrative control if an IdM administrator is targeted. |
|
| CVE-2026-87876 | Sep 09, 2026 |
CUPS Username ACL Bypass via Case-Insensitive ComparisonsTwo case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations. |
And others... |
| CVE-2026-87872 | Sep 09, 2026 |
Ansible community.general OCAPI Modules Disable TLS Validation (CVE-2026-87872)A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re-enable it, while sending HTTP Basic-Auth credentials to an https endpoint. An attacker positioned on the network path between the Ansible controller and the OCAPI-managed storage/enclosure device can present any certificate, intercept the session, capture the credentials, and tamper with responses. |
|
| CVE-2026-87875 | Sep 09, 2026 |
CUPS UTF32ToUTF8 Heap OOB Read via SNMPThe cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content. |
And others... |
| CVE-2026-87853 | Sep 09, 2026 |
SSSD IdP OIDC Subject Prefix Auth FlawA flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP identifier is a strict prefix of a target user's identifier can authenticate as the target user. |
|
| CVE-2026-87874 | Sep 09, 2026 |
Ansible community.general memcached cache plugin RCE via pickle deserializationA flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached is unauthenticated and cache keys are predictable, an attacker able to reach a network-exposed or shared memcached instance can write a crafted pickle payload that is deserialized and executed on the Ansible controller when the poisoned fact cache is next read, leading to remote code execution. |
|
| CVE-2026-87766 | Sep 09, 2026 |
Bubblewrap <0.12.0: Symlink Escape via /oldroot During Sandbox SetupA flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0. |
|
| CVE-2026-19729 | Sep 09, 2026 |
Keycloak Services Path Probing Flaw Allows File System DisclosureA flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm administrator to still submit arbitrary filesystem paths as keystore parameters. This can be used to determine the existence and readability of files on the server, potentially exposing sensitive system information. |
|
| CVE-2026-86564 | Sep 08, 2026 |
DPDK lib/vhost OOB read in virtio-net controlqueue crashA flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash. |
|
| CVE-2026-18090 | Sep 08, 2026 |
gdk-pixbuf ICNS RLE Heap OOB Read/Info Disclosure via Crafted .icnsA flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory. |
|
| CVE-2026-19625 | Sep 08, 2026 |
Quarkus OIDC Introspection Cache Enables CrossTenant Token UseWhen a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional token introspection cache is also enabled, then a valid token issued by the OIDC Provider 1 that can be used to access "/oidc-provider1" can also be used to access "/oidc-provider2" that is secured by another OIDC Provider 2. |
|
| CVE-2026-19651 | Sep 08, 2026 |
IBM Quarkus 3.27.x-3.27.5 / 3.33.x Auth Bypass via URL QueryIBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input. |
|
| CVE-2026-80219 | Sep 08, 2026 |
OAuth Redirect URI Tampering in hawtio-operator Cluster ModeA flaw was found in hawtio-operator. When deploying Hawtio in cluster mode, the operator creates a cluster-scoped OAuthClient with automatic grant approval (GrantMethod: auto) and no client secret (public client). The redirect URIs are derived from the operator-created Route, whose hostname is tenant-controlled via the Hawtio CR spec.routeHostName field. A malicious tenant can register an arbitrary hostname as a valid OAuth redirect target and, because grants are auto-approved, obtain OpenShift access tokens of any cluster user who visits the crafted authorization URL without any consent prompt. |
|
| CVE-2026-78234 | Sep 08, 2026 |
Privilege Escalation in hawtio-operator: Service-CA Signed Cert AbuseA flaw was found in hawtio-operator. The operator reads the OpenShift Service CA private signing key from the openshift-service-ca namespace and uses it to mint client certificates with a Subject Common Name (CN) supplied by the author of a namespaced Hawtio custom resource. Because the operator ships a ClusterRole that aggregates Hawtio CR permissions into the edit and admin roles, any user with edit access in any namespace can obtain a Service-CA-signed certificate with an arbitrary subject. This certificate can be used to impersonate any in-cluster service identity to peers that trust the Service CA for client authentication, including Jolokia agents and other Service-CA-trusting components. |
|
| CVE-2026-77968 | Sep 08, 2026 |
RedHat hawtio-operator IAM Escalation via widescope ClusterRoleA flaw was found in hawtio-operator. The operator's ClusterRole grants secrets: [create, get, list, update, watch] across all namespaces. While the operator uses a controller-runtime label-selector cache as a memory optimization, the ServiceAccount token authorizes read access to every Secret in the cluster. The operator also bypasses the cache via direct API calls. Compromise of the operator pod would yield read access to every Secret in the cluster, including bootstrap tokens, cloud credentials, and other operators' secrets. |
|
| CVE-2026-74860 | Sep 08, 2026 |
libxml2 Python SAX Binding Double-Free DoS CVE-2026-74860A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings. |
And others... |
| CVE-2026-74859 | Sep 08, 2026 |
GnomeTweaks ZIP Extraction Path Traversal in Theme InstallerThe shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files outside ~/.themes by using ../ path traversal, absolute paths, or symlink entries. |
|
| CVE-2026-76561 | Sep 08, 2026 |
Dogtag PKI ExternalProcessConstraint RCE via Unvalidated Profile ImportA flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account. |
|
| CVE-2026-86469 | Sep 07, 2026 |
Race Condition in GLib2 g_file_replace() Enables File RedirectA flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file. |
And others... |
| CVE-2026-19843 | Sep 07, 2026 |
Privilege Escalation via LDAP Shell Injection in 389 ConsoleA flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell command string without proper escaping. An LDAP user with delegated privileges to create or rename directory entries could craft a malicious DN containing shell metacharacters. When a Cockpit administrator subsequently views the entry in the 389 Console, the embedded shell command executes with root privileges on the directory server host. |
And others... |
| CVE-2026-18922 | Sep 07, 2026 |
389 DS Stale Identity Exploit via SASL PLAIN AuthA flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated successful bind, regardless of which SASL mechanism completes that second bind. An attacker can send a SASL PLAIN bind as cn=Directory Manager with an incorrect password, then complete a SASL ANONYMOUS bind on the same connection, causing the server to grant Directory Manager authority without any valid credentials. A variant using a valid low-privileged account's own successful bind instead of an anonymous one is also possible. |
And others... |
| CVE-2026-18453 | Sep 07, 2026 |
389 Directory Server NULL Pointer Crash via USE_ONE_BACKEND ControlA flaw was found in 389 Directory Server. A missing NULL pointer check in the paged results handling of op_shared_search allows an unauthenticated remote attacker to crash the LDAP server by sending a crafted sequence of search requests using the USE_ONE_BACKEND control, resulting in denial of service. |
And others... |
| CVE-2026-18355 | Sep 07, 2026 |
389-DS SASL I/O Heap Overflow via Small-Length UnderflowA heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(), the wrapped-record length read from the wire is validated only against an upper bound. A small wire length (0, 1, or 2) produces an encrypted_buffer_count below the already-consumed encrypted_buffer_offset, causing an unsigned subtraction underflow in sasl_io_read_packet(). PR_Recv is then requested to read approximately 4 GiB into a 1024-byte heap buffer, resulting in a heap buffer overflow with attacker-controlled content. After a successful SASL bind with integrity protection (SSF > 0), a remote authenticated attacker can cause a denial of service or potentially achieve remote code execution. This flaw is distinct from CVE-2026-11774, whose fix only guards against upper-bound overflow. |
And others... |
| CVE-2026-76560 | Sep 07, 2026 |
Unauth LDAP Client Bypasses SELFDN ACI in 389 DSA flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. This can allow an anonymous LDAP client to perform an operation, such as adding or modifying a directory entry, that a SELFDN-based ACI intended to restrict to a specific authenticated user. |
And others... |
| CVE-2026-79678 | Sep 07, 2026 |
FreeIPA idp-add Eval() RCE & DoS via Unvalidated --organizationA flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via memory exhaustion. |
|
| CVE-2026-76578 | Sep 07, 2026 |
FreeIPA LDAP ACI Flaw Grants Unauth Admin PrivilegesA flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a related flaw in the underlying directory server's ACI evaluation (tracked separately), to create an arbitrary attacker-controlled Kerberos principal and have it added to the administrators group. This allows a remote, unauthenticated attacker to obtain genuine FreeIPA administrator-group membership and perform administrative operations against the directory and, on SID-enabled deployments, other IdM services. |
|
| CVE-2026-86404 | Sep 07, 2026 |
Red Hat EAP Artemis deserialization allows all classes by defaultEAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list/block-list filtering via its checkSecurity()/isTrustedType() method. However, by default both allow-list and block-list are empty. When the allow-list is empty (size == 0), isTrustedType() returns true for ALL classes. This means all classes are deserializable by default. |
And others... |
| CVE-2026-86332 | Sep 07, 2026 |
Red Hat OpenShift AI odh-dashboard: Unchecked K8s Secret read via BFFA flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResource reads Kubernetes Secrets using the dashboard service account and returns the full Secret object, including .data, without an authorization check. Any authenticated dashboard user can retrieve the cluster NVIDIA NGC API key Secret (apiKeySecret) and the NIM image pull secret (nimPullSecret). Create and delete of the same NIM credential are admin-gated; the read path is not. This is missing authorization (CWE-862) and insufficiently protected credentials (CWE-522). It is distinct from CVE-2026-5483 (service-account token leak in the Kubernetes client response wrapper on the same route) and CVE-2026-16456 (odh-model-controller cross-namespace confused deputy). |
|