VulnSea

Tagged “red-hat”

CVEs tagged red-hat, newest first.

2956 CVEsRSS

CVE-2026-15555High· 8.8
1mo ago

A flaw was found in JBoss marshalling

A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on …

▾ TwilightRed Hat · org.jboss.eap/wildfly-clustering-infinispan-marshallingEPSS 0.32%via NVD
CVE-2026-15554High· 7.4
1mo ago

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentica…

▾ TwilightRed Hat · io.undertow/undertow-coreEPSS 0.35%via NVD
CVE-2026-15560High· 8.1
1mo ago

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in…

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in…

▾ TwilightRed Hat · org.jboss.eap/wildfly-iiop-openjdkEPSS 0.57%via NVD
CVE-2026-10579Critical· 9.8
1mo ago

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could l…

▾ MidnightRed Hat · org.picketlink/picketlink-federationEPSS 0.32%via NVD
CVE-2026-72693High· 7.8
1mo ago

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc…

▾ TwilightRed Hat · kbdEPSS 0.16%via NVD
CVE-2026-73077High· 8.4
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.vim filetype plugins pass attacker-controlled Visual-mode selections from K through keywo…

▾ Twilightvim · vimEPSS 0.14%via NVD
CVE-2026-73078High· 8.6
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autoload/netrw.vim constructs Bookmarks, History, and Targets menu entries by interpolating at…

▾ Twilightvim · vimEPSS 0.34%via NVD
CVE-2026-73076High· 8.4
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord to overwrite the installation record with attacker-chosen commands. When vimball#RmVimb…

▾ Twilightvim · vimEPSS 0.13%via NVD
CVE-2026-73242Critical· 9.1⚖ disputed
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using …

▾ Midnightfreerdp · freerdpEPSS 0.40%via NVD
CVE-2026-73241High· 7.5
1mo ago

FreeRDP is a free implementation of the Remote Desktop Protocol

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES PDU while rdstls_server_authenticate is waitin…

▾ Twilightfreerdp · freerdpEPSS 0.47%via NVD
CVE-2026-73072High· 7.8PoC
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_S…

▾ MidnightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.13%via NVD
CVE-2026-73066High· 7.1
1mo ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolv…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.13%via NVD
CVE-2026-19546High· 8.8
1mo ago

A flaw was found in DBI

A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mitigation please reffer to the original https://access.redhat.com/security/cve/cve-2026-19…

▾ TwilightRed Hat · perl-DBIEPSS 0.35%via NVD
CVE-2026-72694High· 7.1
1mo ago

A flaw was found in MRTG

A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a s…

▾ TwilightRed Hat · mrtgEPSS 0.17%via NVD
CVE-2026-66808High· 8.8
1mo ago

Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 2.0%via CVEORG
CVE-2026-66805High· 8.8
1mo ago

Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

▾ TwilightMicrosoft · Microsoft SharePoint Enterprise Server 2016EPSS 2.0%via CVEORG
CVE-2026-71845Medium· 6.3
1mo ago

A flaw was found in insights-client

A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to le…

▾ Sunlitredhat · advanced_cluster_management_for_kubernetesEPSS 0.50%via NVD
CVE-2026-71475Medium· 6.8
1mo ago

A flaw was found in insights-client

A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly…

▾ Sunlitredhat · advanced_cluster_management_for_kubernetesEPSS 0.69%via NVD
CVE-2026-71474High· 7.1
1mo ago

A flaw was found in insights-client

A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read t…

▾ Twilightredhat · advanced_cluster_management_for_kubernetesEPSS 0.16%via NVD
CVE-2026-71468Medium· 5.3
1mo ago

A flaw was found in acm-search-v2-api-rhel9

A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authent…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.11EPSS 0.42%via NVD
CVE-2026-73283Low· 2.5⚖ disputed
1mo ago

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

▾ Sunlitopenbsd · opensshEPSS 0.09%via NVD
CVE-2026-73282Medium· 4.8
1mo ago

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

▾ Sunlitopenbsd · opensshEPSS 0.16%via NVD
CVE-2026-73281Low· 3.5
1mo ago

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bin…

▾ Sunlitopenbsd · opensshEPSS 0.16%via NVD
CVE-2026-73088High· 7.5
1mo ago

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist()…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.66%via NVD
CVE-2026-73089High· 7.5
1mo ago

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCac…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.66%via NVD
CVE-2026-18710Medium· 6.5
1mo ago

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to application log output in cleartext during routine client initialization. This occurs automatic…

▾ Sunlitmongodb · java_driverEPSS 0.14%via NVD
CVE-2026-70622Medium· 6.5
1mo ago

tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-con…

tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read files outside the intended source root directory by planting symlinks in an attacker-con…

▾ SunlitRed Hat · Red Hat OpenShift Update ServiceEPSS 0.46%via NVD
CVE-2026-18618High· 7.5
1mo ago

A flaw was found in ml-metadata

A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service (DoS) issues. An in-cluster attacker, with network access to the MLMD pod, could exploit…

▾ TwilightRed Hat · rhoai/odh-mlmd-grpc-server-rhel9EPSS 0.83%via NVD
CVE-2026-71577Medium· 6.3
1mo ago

A flaw was found in multicluster-global-hub

A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared communication topic. This allows a compromised managed hub to intercept and collect sen…

▾ SunlitRed Hat · multicluster-globalhub/multicluster-globalhub-rhel9-operatorEPSS 0.40%via NVD
CVE-2026-15467High· 8.1
1mo ago

A flaw was found in the trustyai-service-operator's LMEvalJob controller

A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by configuring a sidecar container to bypass existing security policies. This allows the us…

▾ TwilightRed Hat · rhoai/odh-trustyai-service-operator-rhel9EPSS 0.60%via NVD
CVEs tagged “red-hat” — page 67 · VulnSea