Red Hat Linux OS and other open source products
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Red Hat product.
RSS Feeds for Red Hat security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Red Hat products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Red Hat Sorted by Most Security Vulnerabilities since 2018
Red Hat Enterprise Linux Server1534 vulnerabilities
RedHat Enterprise Linux (RHEL) Server. Includes software bundeled with RHEL server.
Red Hat Enterprise Linux Workstation1504 vulnerabilities
RedHat Enterprise Linux (RHEL) Workstation. Includes software bundled with RHEL Workstation.
Red Hat Enterprise Linux Desktop1493 vulnerabilities
RedHat Enterprise Linux (RHEL) Desktop. Includes software bundled with RHEL desktop
Recent Red Hat Security Advisories
| Advisory | Title | Published |
|---|---|---|
| RHSA-2026:67609 | (RHSA-2026:67609) Important: leapp-repository security update | September 15, 2026 |
| RHSA-2026:67608 | (RHSA-2026:67608) Important: leapp-repository security update | September 15, 2026 |
| RHSA-2026:67604 | (RHSA-2026:67604) Important: Red Hat JBoss Enterprise Application Platform 7.4.25 security update | September 15, 2026 |
| RHSA-2026:67603 | (RHSA-2026:67603) Important: Red Hat JBoss Enterprise Application Platform 7.4.25 security update | September 15, 2026 |
| RHSA-2026:67530 | (RHSA-2026:67530) Important: .NET 10.0 security, bug fix, and enhancement update | September 15, 2026 |
| RHSA-2026:67525 | (RHSA-2026:67525) Moderate: .NET 8.0 security, bug fix, and enhancement update | September 15, 2026 |
| RHSA-2026:67524 | (RHSA-2026:67524) Moderate: .NET 8.0 security, bug fix, and enhancement update | September 15, 2026 |
| RHSA-2026:66376 | (RHSA-2026:66376) Important: OpenShift Container Platform 4.20.38 bug fix and security update | September 15, 2026 |
| RHSA-2026:66357 | (RHSA-2026:66357) Important: OpenShift Container Platform 4.22.14 bug fix and security update | September 15, 2026 |
| RHSA-2026:66375 | (RHSA-2026:66375) Important: OpenShift Container Platform 4.20.38 packages and security update | September 15, 2026 |
By the Year
In 2026 there have been 3285 vulnerabilities in Red Hat with an average score of 7.2 out of ten. Last year, in 2025 Red Hat had 1178 security vulnerabilities published. That is, 2107 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.37.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 3285 | 7.23 |
| 2025 | 1178 | 6.86 |
| 2024 | 1695 | 6.82 |
| 2023 | 1207 | 6.74 |
| 2022 | 1362 | 6.96 |
| 2021 | 1123 | 6.61 |
| 2020 | 664 | 6.39 |
| 2019 | 772 | 6.98 |
| 2018 | 760 | 7.16 |
It may take a day or so for new Red Hat vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Red Hat Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-85234 | Sep 15, 2026 |
tftp-hpa OOB Read/Write via Malicious Inverse Remap RuleA flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a non-empty custom error message, it can pass invalid match offsets to the `genmatchstring()` function. This leads to out-of-bounds read/write operations. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted request, causing the daemon to crash and resulting in a denial of service. |
|
| CVE-2026-55225 | Sep 15, 2026 |
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurationsStrimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, an attacker who can create a Kafka custom resource can set Kafka.spec.entityOperator watchedNamespace to a target namespace, causing the Cluster Operator to create a Role with full Secret CRUD permissions there and bind it to the Entity Operator ServiceAccount in the attacker's namespace. The attacker can mint a token for that ServiceAccount and read or write Secrets in any target namespace where the Cluster Operator has been granted permissions, regardless of STRIMZI_NAMESPACE. This issue is fixed in versions 1.0.1 and 1.1.0. |
|
| CVE-2026-79699 | Sep 15, 2026 |
A flaw was found in the containers/storage libraryA flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file when processed by storage/pkg/archive.UnpackLayer, ApplyLayer, or ApplyUncompressedLayer. |
And others... |
| CVE-2026-79705 | Sep 15, 2026 |
A flaw was found in the buildah/copier Go packageA flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended destination. Buildah itself uses chroot hardening and is not affected. |
And others... |
| CVE-2026-85013 | Sep 15, 2026 |
A flaw was found in environment-modulesA flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name, containing shell metacharacters, is evaluated as a command. This can lead to arbitrary command execution in the completing user's shell, impacting their confidentiality, integrity, and availability. |
|
| CVE-2026-91926 | Sep 15, 2026 |
Red Hat: gss-ntlmssp NTLM parser memory leak DoSA flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. The parser allocates memory for each string value but does not free the previous allocation when the same AV_PAIR type appears more than once, leaking the earlier allocation. A malicious or man-in-the-middle server can exploit this to cause gradual memory exhaustion on the client during NTLM authentication, leading to a denial of service. |
|
| CVE-2026-91786 | Sep 15, 2026 |
GNOME Shell OOB Read via Unvalidated Icon Dimensions in D-BusA flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to validate the icon's declared dimensions against the actual data buffer size. A malicious or compromised remote search provider could exploit this by providing oversized icon dimensions, leading to an out-of-bounds read. This can cause the GNOME Shell process to crash, disrupting the user's session, and potentially disclose sensitive information from adjacent memory. |
|
| CVE-2026-75092 | Sep 15, 2026 |
A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository)A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root in the Leapp actor context, bypassing the packaged MySQL systemd unit that normally starts the daemon as User=mysql. A process compromised as the mysql OS identity can write a version-2 persisted configuration (mysqld-auto.cnf) and a malicious shared object into /var/lib/mysql (a directory owned by mysql). That persisted map can set plugin_dir to /var/lib/mysql and early_plugin_load (or related loader options such as plugin_load / plugin_load_add) so MySQL loads the attacker-controlled object during configuration validation. Plugin loading can reach dlopen() before MySQLs runtime-user check and before plugin-symbol validation. When an administrator subsequently runs the documented Leapp preupgrade or upgrade workflow, attacker-controlled code can execute as UID 0 with a full capability set in an unconfined SELinux domain (unconfined_t). The attack does not require write access to the default system plugin path under /usr; redirecting plugin_dir via mysql-owned persisted state is sufficient. Ordinary SQL privileges alone (including highly privileged SQL accounts) are not a sufficient startpoint OS-level execution as the mysql service identity is required, plus later administrator invocation of Leapp. |
And others... |
| CVE-2026-81320 | Sep 15, 2026 |
TLS Private Key Exposed by hawtio-operator via Debug LogA flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object including the TLS private key in PEM format is serialized to JSON and written to the operator's standard output. Operator logs are typically forwarded to centralized logging systems and readable by anyone with pods/log access in the openshift-operators namespace. Debug level 1 is a low threshold commonly enabled during troubleshooting. |
|
| CVE-2026-81303 | Sep 15, 2026 |
Hawtio-Operator Confused Deputy Hostname Subdomain Takeover (CVE-2026-81303)A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into the Route spec without validation or authorization checks. A namespace edit user, who normally cannot set custom Route hostnames, can use the operator as a confused deputy to claim arbitrary externally-routable hostnames, enabling subdomain takeover and, in combination with the auto-grant OAuthClient, OAuth redirect hijack. |
|
| CVE-2026-19816 | Sep 14, 2026 |
PackageKit Dnf5 Backend PrivEsc via SIMULATE Flag BypassA flaw was found in PackageKit. PackageKit skips the polkit authorization check for transactions carrying the SIMULATE (dry-run) flag. In the dnf5 backend, the RepoRemove handler ignores that contract and always executes the real transaction because its guard is written as (role == REPO_REMOVE || !SIMULATE), which is always true for RepoRemove. An unprivileged local user can therefore perform a genuine package uninstall while claiming to simulate. This vulnerability only affects systems using PackageKit with the dnf5 backend. |
|
| CVE-2026-90996 | Sep 14, 2026 |
SSSD NSS Responder DoS via Zero-Length Body (CVE-2026-90996)A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS responder to become unstable or terminate. This vulnerability affects the availability of the system responder. |
|
| CVE-2026-90995 | Sep 14, 2026 |
SSSD PAM Responder NULL Deref DoS via Omitted Service ItemA flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_services` configuration is enabled and the service item is omitted from the request, a NULL pointer dereference can occur. This vulnerability leads to a denial of service, causing the PAM responder to crash and disrupt authentication services. |
|
| CVE-2026-90994 | Sep 14, 2026 |
Local DoS via Empty PAM Request in sssd v1 ParserA flaw was found in sssd, specifically within the PAM (Pluggable Authentication Modules) responder's protocol v1 parser, pam_parse_in_data(). A local client with access to the PAM responder's UNIX socket can exploit this by negotiating protocol v1 and sending an empty or truncated PAM request body. This can trigger an out-of-bounds read, potentially causing the PAM responder to terminate or restart, leading to a local denial of service. |
|
| CVE-2026-90463 | Sep 14, 2026 |
SSSD NSS Responder OOB Read DoS via Crafted LookupsA flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending specially crafted service lookup requests to the NSS responder's UNIX socket, to cause an out-of-bounds read. This out-of-bounds read may lead to a denial of service (DoS) by crashing the NSS responder process. While unprivileged local clients can typically reach the socket, there is no evidence of privilege escalation or reliable data disclosure. |
|
| CVE-2026-90947 | Sep 14, 2026 |
GIMP Lighting Effects OOB Write via Invalid Light SourcesA flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not properly validate the number of light sources. This can lead to an out-of-bounds write, corrupting memory. An attacker could exploit this by convincing a user to open a malicious preset file, potentially causing a crash or enabling arbitrary code execution. |
|
| CVE-2026-90949 | Sep 14, 2026 |
A flaw was found in GIMP's PSP (Paint Shop Pro) file loaderA flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-based buffer overflow can occur due to a mismatch between the allocated buffer size and the amount of data decompressed. A remote attacker could exploit this vulnerability by crafting a malicious PSP file. Opening this file in GIMP could lead to a crash or arbitrary code execution. |
|
| CVE-2026-90948 | Sep 14, 2026 |
A flaw was found in GIMP's ICO file loaderA flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer overflow can occur during the calculation of the required buffer size. This leads to an undersized buffer being allocated, causing a heap-based buffer overflow when the decoded pixel data is written. A remote attacker could exploit this by crafting a malicious ICO file, which, when opened, could lead to arbitrary code execution or a crash. |
|
| CVE-2026-89329 | Sep 11, 2026 |
Red Hat multipathd IPC DoS via blocked listener threadA flaw was found in `multipathd`. A local attacker with access to the `multipathd` UNIX control socket can exploit this vulnerability by sending valid commands and then ceasing to read replies. This action can cause the `multipathd` listener thread to block, leading to a Denial of Service (DoS) where legitimate Inter-Process Communication (IPC) operations may hang or time out. This issue does not result in privilege escalation, arbitrary code execution, or impact data confidentiality or integrity. |
|
| CVE-2026-18495 | Sep 11, 2026 |
libtiff tiff2pdf Heap-BUF Overflow via Truncated StripByteCountsA flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit `StripByteCounts` value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption. |
And others... |
| CVE-2026-89298 | Sep 11, 2026 |
Keycloak DCR Service Leak: Admin Role Reveals Client SecretA flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution. The issue occurs when a user with the view-clients role accesses the client registration endpoint to retrieve client details. Due to a failure to mask sensitive information, the service returns the client's confidential secret in cleartext. This could allow a read-only administrator to obtain full access to the affected client's account and potentially escalate their privileges within the realm. |
|
| CVE-2026-77159 | Sep 11, 2026 |
Privilege Escalation via Symlink Chown in libvirt qemuTPMEmulatorPrepareHostA symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can replace the logfile with a symlink, causing libvirtd (running as root) to transfer ownership of an arbitrary file to the swtpm user. |
|
| CVE-2026-89060 | Sep 11, 2026 |
CVE-2026-89060: multicluster-observability-addon Namespace EscalationA cross-namespace authorization flaw in multicluster-observability-addon allows a user with permission to modify a managed clusters ManagedClusterAddOn configuration to reference ClusterLogForwarder or OpenTelemetryCollector resources outside the permitted namespace. If those resources reference Secrets, the add-on may copy the referenced Secrets to the attacker-controlled managed cluster. |
|
| CVE-2026-88914 | Sep 11, 2026 |
GStreamer gst-plugins-good isomp4 Integer Overflow in Closed-Caption ParserA flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in the caption parser. This leads to an out-of-bounds heap read of up to 244 bytes, which is then included in the downstream caption output. An attacker could exploit this by tricking a user into opening a malicious media file, potentially resulting in disclosure of adjacent heap memory or application crash. |
|
| CVE-2026-88924 | Sep 10, 2026 |
Local Privilege Escalation via TOCTOU in gvfsd-admin (Red Hat)A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race condition and exchange the socket pathname with a symbolic link pointing to an arbitrary root-owned file (such as /etc/pam.d/su). The daemon subsequently follows the symlink and changes the ownership of the targeted root-owned file to the attacker's user ID. This allows an authenticated local attacker to modify critical system files, leading to a full local privilege escalation to root. |
|
| CVE-2026-88859 | Sep 10, 2026 |
Evolution JS Execution via Spoofed vCard Control in HTML EmailA flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler incorrectly assigns an attacker-controlled JavaScript URL to an iframe's source. This action leads to arbitrary JavaScript execution within the mail-viewing context, effectively bypassing the security measures designed to prevent script execution in email content. |
|
| CVE-2026-84828 | Sep 10, 2026 |
PCS: Local File Disclosure via pcs host auth --tokenA flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the files are shorter than 256 bytes. The file contents are read with root privileges by the pcsd daemon and can be exfiltrated by the attacker through subsequent cluster node communication. This allows disclosure of sensitive data such as API keys, tokens, or configuration secrets that would otherwise be inaccessible to the attacker. |
And others... |
| CVE-2026-88265 | Sep 10, 2026 |
CVE-2026-88265: crun 1.29.1 and below pivot_root stdio symlink issueA flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet. |
And others... |
| CVE-2026-88264 | Sep 10, 2026 |
crun 1.29.1: /dev Console Redirect via Terminal Setup Insecure Bind-MountA flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redirect /dev/console onto an attacker-controlled path, including via the read-only-rootfs bind-mount fallback. Affected versions are crun 1.29.1 and earlier. Default configurations that mount a fresh /dev are not exposed. No fixed release is available yet. |
And others... |
| CVE-2026-84042 | Sep 10, 2026 |
crun 1.29+ Priv Esc via PassNet (libkrun)A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The issue is a regression in crun 1.29. It affects crun >= 1.29 |
And others... |
| CVE-2026-44950 | Sep 10, 2026 |
Heap buffer overflow in libXfont2 fs_read_glyphs()fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. Existing checks validates only that the source slice (position, length) lies within the source bitmap buffer. It does not check whether the running destination cursor has exceeded the allocation. A malicious font server can send overlapping source offsets -- for example 1000 glyphs each referencing {position:0, length:64} with nbytes=64. Each individual source range passes the existing validation, but the cumulative writes total 64000 bytes into a 64-byte destination buffer. This is a heap buffer overflow with attacker-controlled content. |
|
| CVE-2026-59679 | Sep 10, 2026 |
OOB Heap Read in libXfont2 query glyphs (CVE-2026-59679)fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using num_chars from the FS_QueryXBitmaps16 reply, but that array was allocated with a size derived from num_extents in the separate FS_QueryXExtents16 reply. The two CARD32 fields are never cross-checked. A malicious or compromised font server can send a small num_extents (e.g. 1) in the extents reply, then a large num_chars (e.g. 100000) in the bitmaps reply. This causes attacker-controlled out-of-bounds heap read and writes. |
|
| CVE-2026-88770 | Sep 10, 2026 |
Keycloak Device Auth Grant Brute-Force Bypass for Locked AccountsA flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue occurs because the token redemption process fails to check if a user account is currently locked due to brute-force protection. If an attacker has an active session for a locked account, they can complete the device login process and receive new security tokens. This allows the attacker to maintain access to the account even when it should be temporarily disabled to prevent unauthorized entry. |
|
| CVE-2026-88763 | Sep 10, 2026 |
SkupperRouter AMQP Parser Recursion DoS (Stack Overflow)A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message using its AMQP field parser. Due to a lack of bounds on recursion during parsing, the router can run out of stack memory and crash, leading to a denial of service for the interconnected network. |
|
| CVE-2026-49362 | Sep 10, 2026 |
Apache Artemis/ActiveMQ Artemis CORE Protocol Durable Queue RCE 2.50.0-2.57.0An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. |
|
| CVE-2026-49363 | Sep 10, 2026 |
Apache Artemis CORE Protocol Topology Disclosure 2.50.0-2.57.0An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. |
|
| CVE-2026-49364 | Sep 10, 2026 |
Apache Artemis: Unauth Capture via Cluster Handshake (2.50-2.56, 1.0-2.44)An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. |
|
| CVE-2026-57822 | Sep 10, 2026 |
Apache Artemis 2.44-2.57 OSS: Java Deserialization DOS in Management RequestsWhen the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that the broker will not utilise. The permitted types allow to craft a payload causing excessive computation and pinning the processing thread, leading to denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.3.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. |
|
| CVE-2026-57967 | Sep 10, 2026 |
Apache Artemis SESSION_REATTACH RCE 2.50.0-2.56.0An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. |
|
| CVE-2026-67593 | Sep 10, 2026 |
Artemis OpenWire RemoveSubscriptionInfo Queue Deletion pre-auth (v2.50.02.56.0)A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. |
|
| CVE-2026-18147 | Sep 09, 2026 |
FreeIPA Web UI DOM XSS in Password ResetA flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and complete a password reset, the attacker could inject and execute arbitrary JavaScript code. This allows the attacker to perform actions within the victim's authenticated session, potentially leading to full administrative control if an IdM administrator is targeted. |
|
| CVE-2026-87876 | Sep 09, 2026 |
CUPS Username ACL Bypass via Case-Insensitive ComparisonsTwo case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations. |
And others... |
| CVE-2026-87872 | Sep 09, 2026 |
Ansible community.general OCAPI Modules Disable TLS Validation (CVE-2026-87872)A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re-enable it, while sending HTTP Basic-Auth credentials to an https endpoint. An attacker positioned on the network path between the Ansible controller and the OCAPI-managed storage/enclosure device can present any certificate, intercept the session, capture the credentials, and tamper with responses. |
|
| CVE-2026-87875 | Sep 09, 2026 |
CUPS UTF32ToUTF8 Heap OOB Read via SNMPThe cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content. |
And others... |
| CVE-2026-87853 | Sep 09, 2026 |
SSSD IdP OIDC Subject Prefix Auth FlawA flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of an exact match. An attacker whose IdP identifier is a strict prefix of a target user's identifier can authenticate as the target user. |
|
| CVE-2026-87874 | Sep 09, 2026 |
Ansible community.general memcached cache plugin RCE via pickle deserializationA flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memcached, which pickles values on write and unpickles them on read. Because memcached is unauthenticated and cache keys are predictable, an attacker able to reach a network-exposed or shared memcached instance can write a crafted pickle payload that is deserialized and executed on the Ansible controller when the poisoned fact cache is next read, leading to remote code execution. |
|
| CVE-2026-87766 | Sep 09, 2026 |
Bubblewrap <0.12.0: Symlink Escape via /oldroot During Sandbox SetupA flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This happens before the sandboxed process starts. This issue is GHSA-pxhw-h44j-8pfx. It is fixed in bubblewrap 0.12.0. |
|
| CVE-2026-19729 | Sep 09, 2026 |
Keycloak Services Path Probing Flaw Allows File System DisclosureA flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm administrator to still submit arbitrary filesystem paths as keystore parameters. This can be used to determine the existence and readability of files on the server, potentially exposing sensitive system information. |
|
| CVE-2026-86564 | Sep 08, 2026 |
DPDK lib/vhost OOB read in virtio-net controlqueue crashA flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash. |
|
| CVE-2026-18090 | Sep 08, 2026 |
gdk-pixbuf ICNS RLE Heap OOB Read/Info Disclosure via Crafted .icnsA flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory. |
|