Red Hat Red Hat Linux OS and other open source products

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Red Hat product.

RSS Feeds for Red Hat security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Red Hat products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Red Hat Sorted by Most Security Vulnerabilities since 2018

Red Hat Enterprise Linux (RHEL)2791 vulnerabilities

Red Hat Enterprise Linux Server1534 vulnerabilities
RedHat Enterprise Linux (RHEL) Server. Includes software bundeled with RHEL server.

Red Hat Enterprise Linux Workstation1504 vulnerabilities
RedHat Enterprise Linux (RHEL) Workstation. Includes software bundled with RHEL Workstation.

Red Hat Enterprise Linux Desktop1493 vulnerabilities
RedHat Enterprise Linux (RHEL) Desktop. Includes software bundled with RHEL desktop

Red Hat Enterprise Linux Eus1169 vulnerabilities

Red Hat Openshift638 vulnerabilities

Red Hat Rhel Eus627 vulnerabilities

Red Hat Rhel E4s533 vulnerabilities

Red Hat Rhel Tus461 vulnerabilities

Red Hat Rhel Aus447 vulnerabilities

Red Hat Satellite369 vulnerabilities

Red Hat Rhel Eus Long Life364 vulnerabilities

Red Hat Rhel Els353 vulnerabilities

Red Hat Openshift Ai329 vulnerabilities

Red Hat Hummingbird307 vulnerabilities

Red Hat Openstack284 vulnerabilities

Red Hat Jbosseapxp241 vulnerabilities

Red Hat Build Keycloak226 vulnerabilities

Red Hat Jboss Fuse213 vulnerabilities

Red Hat Jboss Data Grid199 vulnerabilities

Red Hat Rhivos199 vulnerabilities

Red Hat Single Sign On185 vulnerabilities

Red Hat Acm157 vulnerabilities

Red Hat Quay156 vulnerabilities

Red Hat Openshift Devspaces156 vulnerabilities

Red Hat Enterprise Linux Ai155 vulnerabilities

Red Hat Rhdh127 vulnerabilities

Red Hat Discovery125 vulnerabilities

Red Hat Software Collections123 vulnerabilities

Red Hat Keycloak123 vulnerabilities

Red Hat Cryostat120 vulnerabilities

Red Hat Virtualization115 vulnerabilities

Red Hat Ai Inference Server105 vulnerabilities

Red Hat Kafka104 vulnerabilities

Red Hat Ceph Storage99 vulnerabilities

Red Hat Apache Camel Hawtio98 vulnerabilities

Red Hat Multicluster Engine96 vulnerabilities

Red Hat Single Sign On95 vulnerabilities

Red Hat Openshift Pipelines95 vulnerabilities

Red Hat Rhui94 vulnerabilities

Red Hat Logging91 vulnerabilities

Red Hat Camel Spring Boot88 vulnerabilities

Red Hat Amq Streams84 vulnerabilities

Red Hat Service Mesh84 vulnerabilities

Red Hat Amq Broker79 vulnerabilities

Red Hat Ansible Portal77 vulnerabilities

Red Hat Openshift Lightspeed75 vulnerabilities

Red Hat Serverless75 vulnerabilities

Red Hat Http Server72 vulnerabilities

Red Hat Ansible Tower69 vulnerabilities

Red Hat Openshift Gitops68 vulnerabilities

Red Hat Quarkus67 vulnerabilities

Red Hat 3scale Amp62 vulnerabilities

Red Hat Camel Quarkus59 vulnerabilities

Red Hat Podman Desktop58 vulnerabilities

Red Hat Apicurio Registry57 vulnerabilities

Red Hat Satellite Capsule56 vulnerabilities

Red Hat Rhmt56 vulnerabilities

Red Hat Libvirt55 vulnerabilities

Red Hat Service Registry54 vulnerabilities

Red Hat Multicluster Globalhub54 vulnerabilities

Red Hat Virtualization Host53 vulnerabilities

Red Hat Directory Server53 vulnerabilities

Red Hat Network Observ Optr51 vulnerabilities

Red Hat Jboss Core Services48 vulnerabilities

Red Hat Insights Proxy44 vulnerabilities

Red Hat Ansible42 vulnerabilities

Red Hat Satellite Utils42 vulnerabilities

Recent Red Hat Security Advisories

Advisory Title Published
RHSA-2026:67609 (RHSA-2026:67609) Important: leapp-repository security update September 15, 2026
RHSA-2026:67608 (RHSA-2026:67608) Important: leapp-repository security update September 15, 2026
RHSA-2026:67604 (RHSA-2026:67604) Important: Red Hat JBoss Enterprise Application Platform 7.4.25 security update September 15, 2026
RHSA-2026:67603 (RHSA-2026:67603) Important: Red Hat JBoss Enterprise Application Platform 7.4.25 security update September 15, 2026
RHSA-2026:67530 (RHSA-2026:67530) Important: .NET 10.0 security, bug fix, and enhancement update September 15, 2026
RHSA-2026:67525 (RHSA-2026:67525) Moderate: .NET 8.0 security, bug fix, and enhancement update September 15, 2026
RHSA-2026:67524 (RHSA-2026:67524) Moderate: .NET 8.0 security, bug fix, and enhancement update September 15, 2026
RHSA-2026:66376 (RHSA-2026:66376) Important: OpenShift Container Platform 4.20.38 bug fix and security update September 15, 2026
RHSA-2026:66357 (RHSA-2026:66357) Important: OpenShift Container Platform 4.22.14 bug fix and security update September 15, 2026
RHSA-2026:66375 (RHSA-2026:66375) Important: OpenShift Container Platform 4.20.38 packages and security update September 15, 2026

By the Year

In 2026 there have been 3285 vulnerabilities in Red Hat with an average score of 7.2 out of ten. Last year, in 2025 Red Hat had 1178 security vulnerabilities published. That is, 2107 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.37.




Year Vulnerabilities Average Score
2026 3285 7.23
2025 1178 6.86
2024 1695 6.82
2023 1207 6.74
2022 1362 6.96
2021 1123 6.61
2020 664 6.39
2019 772 6.98
2018 760 7.16

It may take a day or so for new Red Hat vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Red Hat Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-85234 Sep 15, 2026
tftp-hpa OOB Read/Write via Malicious Inverse Remap Rule A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a non-empty custom error message, it can pass invalid match offsets to the `genmatchstring()` function. This leads to out-of-bounds read/write operations. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted request, causing the daemon to crash and resulting in a denial of service.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-55225 Sep 15, 2026
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, an attacker who can create a Kafka custom resource can set Kafka.spec.entityOperator watchedNamespace to a target namespace, causing the Cluster Operator to create a Role with full Secret CRUD permissions there and bind it to the Entity Operator ServiceAccount in the attacker's namespace. The attacker can mint a token for that ServiceAccount and read or write Secrets in any target namespace where the Cluster Operator has been granted permissions, regardless of STRIMZI_NAMESPACE. This issue is fixed in versions 1.0.1 and 1.1.0.
Kafka
CVE-2026-79699 Sep 15, 2026
A flaw was found in the containers/storage library A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file when processed by storage/pkg/archive.UnpackLayer, ApplyLayer, or ApplyUncompressedLayer.
Ansible Automation Platform
Enterprise Linux (RHEL)
Hummingbird
And others...
CVE-2026-79705 Sep 15, 2026
A flaw was found in the buildah/copier Go package A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended destination. Buildah itself uses chroot hardening and is not affected.
Ansible Automation Platform
Enterprise Linux (RHEL)
Hummingbird
And others...
CVE-2026-85013 Sep 15, 2026
A flaw was found in environment-modules A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name, containing shell metacharacters, is evaluated as a command. This can lead to arbitrary command execution in the completing user's shell, impacting their confidentiality, integrity, and availability.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-91926 Sep 15, 2026
Red Hat: gss-ntlmssp NTLM parser memory leak DoS A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. The parser allocates memory for each string value but does not free the previous allocation when the same AV_PAIR type appears more than once, leaking the earlier allocation. A malicious or man-in-the-middle server can exploit this to cause gradual memory exhaustion on the client during NTLM authentication, leading to a denial of service.
Enterprise Linux (RHEL)
CVE-2026-91786 Sep 15, 2026
GNOME Shell OOB Read via Unvalidated Icon Dimensions in D-Bus A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to validate the icon's declared dimensions against the actual data buffer size. A malicious or compromised remote search provider could exploit this by providing oversized icon dimensions, leading to an out-of-bounds read. This can cause the GNOME Shell process to crash, disrupting the user's session, and potentially disclose sensitive information from adjacent memory.
Enterprise Linux (RHEL)
CVE-2026-75092 Sep 15, 2026
A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository) A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the packaged MySQL systemd unit that normally starts the daemon as User=mysql. A process compromised as the mysql OS identity can write a version-2 persisted configuration (mysqld-auto.cnf) and a malicious shared object into /var/lib/mysql (a directory owned by mysql). That persisted map can set plugin_dir to /var/lib/mysql and early_plugin_load (or related loader options such as plugin_load / plugin_load_add) so MySQL loads the attacker-controlled object during configuration validation. Plugin loading can reach dlopen() before MySQLs runtime-user check and before plugin-symbol validation. When an administrator subsequently runs the documented Leapp preupgrade or upgrade workflow, attacker-controlled code can execute as UID 0 with a full capability set in an unconfined SELinux domain (unconfined_t). The attack does not require write access to the default system plugin path under /usr; redirecting plugin_dir via mysql-owned persisted state is sufficient. Ordinary SQL privileges alone (including highly privileged SQL accounts) are not a sufficient startpoint OS-level execution as the mysql service identity is required, plus later administrator invocation of Leapp.
Enterprise Linux (RHEL)
Openstack
Rhel Eus
And others...
CVE-2026-81320 Sep 15, 2026
TLS Private Key Exposed by hawtio-operator via Debug Log A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object including the TLS private key in PEM format is serialized to JSON and written to the operator's standard output. Operator logs are typically forwarded to centralized logging systems and readable by anyone with pods/log access in the openshift-operators namespace. Debug level 1 is a low threshold commonly enabled during troubleshooting.
Apache Camel Hawtio
CVE-2026-81303 Sep 15, 2026
Hawtio-Operator Confused Deputy Hostname Subdomain Takeover (CVE-2026-81303) A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into the Route spec without validation or authorization checks. A namespace edit user, who normally cannot set custom Route hostnames, can use the operator as a confused deputy to claim arbitrary externally-routable hostnames, enabling subdomain takeover and, in combination with the auto-grant OAuthClient, OAuth redirect hijack.
Apache Camel Hawtio
CVE-2026-19816 Sep 14, 2026
PackageKit Dnf5 Backend PrivEsc via SIMULATE Flag Bypass A flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend.
Enterprise Linux (RHEL)
CVE-2026-90996 Sep 14, 2026
SSSD NSS Responder DoS via Zero-Length Body (CVE-2026-90996) A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become unstable or terminate. This vulnerability affects the availability of the system responder.
Enterprise Linux (RHEL)
Openshift
CVE-2026-90995 Sep 14, 2026
SSSD PAM Responder NULL Deref DoS via Omitted Service Item A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_services` configuration is enabled and the service item is omitted from the request, a NULL pointer dereference can occur. This vulnerability leads to a denial of service, causing the PAM responder to crash and disrupt authentication services.
Enterprise Linux (RHEL)
Openshift
CVE-2026-90994 Sep 14, 2026
Local DoS via Empty PAM Request in sssd v1 Parser A flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the PAM responder's UNIX socket can exploit this by negotiating protocol v1 and sending an empty or truncated PAM request body. This can trigger an out-of-bounds read, potentially causing the PAM responder to terminate or restart, leading to a local denial of service.
Enterprise Linux (RHEL)
Openshift
CVE-2026-90463 Sep 14, 2026
SSSD NSS Responder OOB Read DoS via Crafted Lookups A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to cause an out-of-bounds read. This out-of-bounds read may lead to a denial of service (DoS) by crashing the NSS responder process. While unprivileged local clients can typically reach the socket, there is no evidence of privilege escalation or reliable data disclosure.
Enterprise Linux (RHEL)
Openshift
CVE-2026-90947 Sep 14, 2026
GIMP Lighting Effects OOB Write via Invalid Light Sources A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not properly validate the number of light sources. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to open a malicious preset file, potentially causing a crash or enabling arbitrary code execution.
Enterprise Linux (RHEL)
CVE-2026-90949 Sep 14, 2026
A flaw was found in GIMP's PSP (Paint Shop Pro) file loader A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size and the amount of data decompressed. A remote attacker could exploit this vulnerability by crafting a malicious PSP file. Opening this file in GIMP could lead to a crash or arbitrary code execution.
Enterprise Linux (RHEL)
CVE-2026-90948 Sep 14, 2026
A flaw was found in GIMP's ICO file loader A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This leads to an undersized buffer being allocated, causing a heap-based buffer overflow when the decoded pixel data is written. A remote attacker could exploit this by crafting a malicious ICO file, which, when opened, could lead to arbitrary code execution or a crash.
Enterprise Linux (RHEL)
CVE-2026-89329 Sep 11, 2026
Red Hat multipathd IPC DoS via blocked listener thread A flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity.
Enterprise Linux (RHEL)
Openshift
CVE-2026-18495 Sep 11, 2026
libtiff tiff2pdf Heap-BUF Overflow via Truncated StripByteCounts A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.
Hummingbird
Ceph Storage
Enterprise Linux (RHEL)
And others...
CVE-2026-89298 Sep 11, 2026
Keycloak DCR Service Leak: Admin Role Reveals Client Secret A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution. The issue occurs when a user with the view-clients role accesses the client registration endpoint to retrieve client details. Due to a failure to mask sensitive information, the service returns the client's confidential secret in cleartext. This could allow a read-only administrator to obtain full access to the affected client's account and potentially escalate their privileges within the realm.
Build Keycloak
Red Hat Single Sign On
CVE-2026-77159 Sep 11, 2026
Privilege Escalation via Symlink Chown in libvirt qemuTPMEmulatorPrepareHost A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can replace the logfile with a symlink, causing libvirtd (running as root) to transfer ownership of an arbitrary file to the swtpm user.
Enterprise Linux (RHEL)
CVE-2026-89060 Sep 11, 2026
CVE-2026-89060: multicluster-observability-addon Namespace Escalation A cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed clusters ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster.
Acm
CVE-2026-88914 Sep 11, 2026
GStreamer gst-plugins-good isomp4 Integer Overflow in Closed-Caption Parser A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes, which is then included in the downstream caption output. An attacker could exploit this by tricking a user into opening a malicious media file, potentially resulting in disclosure of adjacent heap memory or application crash.
Enterprise Linux (RHEL)
CVE-2026-88924 Sep 10, 2026
Local Privilege Escalation via TOCTOU in gvfsd-admin (Red Hat) A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root.
Enterprise Linux (RHEL)
CVE-2026-88859 Sep 10, 2026
Evolution JS Execution via Spoofed vCard Control in HTML Email A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler incorrectly assigns an attacker-controlled JavaScript URL to an iframe's source. This action leads to arbitrary JavaScript execution within the mail-viewing context, effectively bypassing the security measures designed to prevent script execution in email content.
Enterprise Linux (RHEL)
CVE-2026-84828 Sep 10, 2026
PCS: Local File Disclosure via pcs host auth --token A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the files are shorter than 256 bytes. The file contents are read with root privileges by the pcsd daemon and can be exfiltrated by the attacker through subsequent cluster node communication. This allows disclosure of sensitive data such as API keys, tokens, or configuration secrets that would otherwise be inaccessible to the attacker.
Enterprise Linux (RHEL)
Openshift
Openstack
And others...
CVE-2026-88265 Sep 10, 2026
CVE-2026-88265: crun 1.29.1 and below pivot_root stdio symlink issue A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.
Hummingbird
Enterprise Linux (RHEL)
Openshift
And others...
CVE-2026-88264 Sep 10, 2026
crun 1.29.1: /dev Console Redirect via Terminal Setup Insecure Bind-Mount A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet.
Hummingbird
Enterprise Linux (RHEL)
Openshift
And others...
CVE-2026-84042 Sep 10, 2026
crun 1.29+ Priv Esc via PassNet (libkrun) A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The issue is a regression in crun 1.29. It affects crun >= 1.29
Hummingbird
Enterprise Linux (RHEL)
Openshift
And others...
CVE-2026-44950 Sep 10, 2026
Heap buffer overflow in libXfont2 fs_read_glyphs() fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination cursor has exceeded the allocation. A malicious font server can send overlapping source offsets -- for example 1000 glyphs each referencing {position:0, length:64} with nbytes=64. Each individual source range passes the existing validation, but the cumulative writes total 64000 bytes into a 64-byte destination buffer. This is a heap buffer overflow with attacker-controlled content.
CVE-2026-59679 Sep 10, 2026
OOB Heap Read in libXfont2 query glyphs (CVE-2026-59679) fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked. A malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. This causes attacker-controlled out-of-bounds heap read and writes.
CVE-2026-88770 Sep 10, 2026
Keycloak Device Auth Grant Brute-Force Bypass for Locked Accounts A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue occurs because the token redemption process fails to check if a user account is currently locked due to brute-force protection. If an attacker has an active session for a locked account, they can complete the device login process and receive new security tokens. This allows the attacker to maintain access to the account even when it should be temporarily disabled to prevent unauthorized entry.
Build Keycloak
Red Hat Single Sign On
CVE-2026-88763 Sep 10, 2026
SkupperRouter AMQP Parser Recursion DoS (Stack Overflow) A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message using its AMQP field parser. Due to a lack of bounds on recursion during parsing, the router can run out of stack memory and crash, leading to a denial of service for the interconnected network.
Service Interconnect
CVE-2026-49362 Sep 10, 2026
Apache Artemis/ActiveMQ Artemis CORE Protocol Durable Queue RCE 2.50.0-2.57.0 An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
CVE-2026-49363 Sep 10, 2026
Apache Artemis CORE Protocol Topology Disclosure 2.50.0-2.57.0 An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
CVE-2026-49364 Sep 10, 2026
Apache Artemis: Unauth Capture via Cluster Handshake (2.50-2.56, 1.0-2.44) An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
CVE-2026-57822 Sep 10, 2026
Apache Artemis 2.44-2.57 OSS: Java Deserialization DOS in Management Requests When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that the broker will not utilise. The permitted types allow to craft a payload causing excessive computation and pinning the processing thread, leading to denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.3.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
CVE-2026-57967 Sep 10, 2026
Apache Artemis SESSION_REATTACH RCE 2.50.0-2.56.0 An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
CVE-2026-67593 Sep 10, 2026
Artemis OpenWire RemoveSubscriptionInfo Queue Deletion pre-auth (v2.50.02.56.0) A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
CVE-2026-18147 Sep 09, 2026
FreeIPA Web UI DOM XSS in Password Reset A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inject and execute arbitrary JavaScript code. This allows the attacker to perform actions within the victim's authenticated session, potentially leading to full administrative control if an IdM administrator is targeted.
Enterprise Linux (RHEL)
CVE-2026-87876 Sep 09, 2026
CUPS Username ACL Bypass via Case-Insensitive Comparisons Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-87872 Sep 09, 2026
Ansible community.general OCAPI Modules Disable TLS Validation (CVE-2026-87872) A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re-enable it, while sending HTTP Basic-Auth credentials to an https endpoint. An attacker positioned on the network path between the Ansible controller and the OCAPI-managed storage/enclosure device can present any certificate, intercept the session, capture the credentials, and tamper with responses.
Ceph Storage
Openstack
CVE-2026-87875 Sep 09, 2026
CUPS UTF32ToUTF8 Heap OOB Read via SNMP The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.
Enterprise Linux (RHEL)
Hummingbird
Openshift
And others...
CVE-2026-87853 Sep 09, 2026
SSSD IdP OIDC Subject Prefix Auth Flaw A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP identifier is a strict prefix of a target user's identifier can authenticate as the target user.
Enterprise Linux (RHEL)
Openshift
CVE-2026-87874 Sep 09, 2026
Ansible community.general memcached cache plugin RCE via pickle deserialization A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached is unauthenticated and cache keys are predictable, an attacker able to reach a network-exposed or shared memcached instance can write a crafted pickle payload that is deserialized and executed on the Ansible controller when the poisoned fact cache is next read, leading to remote code execution.
Ceph Storage
Openstack
CVE-2026-87766 Sep 09, 2026
Bubblewrap <0.12.0: Symlink Escape via /oldroot During Sandbox Setup A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0.
Enterprise Linux (RHEL)
Hummingbird
CVE-2026-19729 Sep 09, 2026
Keycloak Services Path Probing Flaw Allows File System Disclosure A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm administrator to still submit arbitrary filesystem paths as keystore parameters. This can be used to determine the existence and readability of files on the server, potentially exposing sensitive system information.
Build Keycloak
Red Hat Single Sign On
CVE-2026-86564 Sep 08, 2026
DPDK lib/vhost OOB read in virtio-net controlqueue crash A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.
Enterprise Linux (RHEL)
Openshift
CVE-2026-18090 Sep 08, 2026
gdk-pixbuf ICNS RLE Heap OOB Read/Info Disclosure via Crafted .icns A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.
Enterprise Linux (RHEL)
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.