VulnSea

Red Hat has 1,283 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1041 in the last 90 days against 120 in the 90 before. The busiest recent month was September 2026 with 636. The median CVSS is 7.0 (high), with 58 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (97) and CWE-825 (89). Most affected products: Red Hat Enterprise Linux 9 (212), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
—(1)
Last 90 days
1041 prev 120

Products

  • Red Hat Enterprise Linux 9 212
  • Red Hat OpenShift Container Platform 4 95
  • Red Hat Enterprise Linux 10 62
  • Linux 57
  • Red Hat OpenShift AI (RHOAI) 45
  • Red Hat Enterprise Linux BaseOS (v. 10) 36
1283
Total CVEs
58
Critical
1
CISA KEV
1
Exploited

Red Hat vulnerabilities

CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.

1283 CVEsRSS

CVE-2026-84720Medium· 6.5
4d ago

A flaw was found in the Ansible Automation Platform automation-controller

A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats artifacts propagated between workflow nodes, is not wrapped in preve…

▾ SunlitRed Hat · automation-controllerEPSS 0.27%via NVD
CVE-2026-84719Critical· 9.9
4d ago

A flaw was found in the Ansible Automation Platform automation-controller

A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node a…

▾ MidnightRed Hat · automation-controllerEPSS 0.43%via NVD
CVE-2026-84718Medium· 4.3
4d ago

A flaw was found in the Ansible Automation Platform automation-controller

A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's client IP without verifying that it ori…

▾ SunlitRed Hat · automation-controllerEPSS 0.14%via NVD
CVE-2026-84717Medium· 5.3
4d ago

A flaw was found in the Ansible Automation Platform automation-controller

A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target…

▾ SunlitRed Hat · automation-controllerEPSS 0.34%via NVD
CVE-2026-84716Medium· 6.6
4d ago

A flaw was found in the automation-controller instance install-bundle endpoint

A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administrator downloads an execution/hop node's install bundle, the controller signs an X…

▾ SunlitRed Hat · automation-controllerEPSS 0.18%via NVD
CVE-2026-84714High· 7.1
4d ago

A flaw was found in the automation-controller input-validation guard sanitize_jinja()

A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function uses two regular expressions to reject user-supplied Jinja, but the patterns stop a…

▾ TwilightRed Hat · automation-controllerEPSS 0.29%via NVD
CVE-2026-84713Medium· 6.5
4d ago

A flaw was found in the automation-controller notification subsystem

A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.notification_ configuration is protected from API filtering, its recipient value is…

▾ SunlitRed Hat · ansible-automation-platform-27/controller-rhel9EPSS 0.31%via NVD
CVE-2026-84712Medium· 5.3
4d ago

A flaw was found in the automation-controller API

A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/ping/ (ApiV2PingView, AllowAny) over-serializes RBAC-gated automation-mesh data in…

▾ SunlitRed Hat · automation-controllerEPSS 0.34%via NVD
CVE-2026-84706High· 7.6
4d ago

A flaw was found in Ansible Automation Platform's automation-controller

A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that om…

▾ TwilightRed Hat · automation-controllerEPSS 0.31%via NVD
CVE-2026-75884Critical· 9.1
4d ago

A flaw was found in AWX

A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service…

▾ MidnightRed Hat · automation-controllerEPSS 0.41%via NVD
CVE-2026-84691High· 8.7
4d ago

A flaw was found in Red Hat Ansible Automation Platform's automation- controller

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is rendered with a li…

▾ TwilightRed Hat · automation-controllerEPSS 0.20%via NVD
CVE-2026-84683High· 8.7
4d ago

A flaw was found in Red Hat Ansible Automation Platform's automation- controller

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacters but does not remove ANSI terminal es…

▾ TwilightRed Hat · automation-controllerEPSS 0.26%via NVD
CVE-2026-96546Low· 2.5PoC
4d ago

A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader

A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompressed DDS image, the file-dds plug-in performs an unconditional one-byte look-ahead after processing the final pixel. …

▾ TwilightRed Hat · gimpEPSS 0.11%via NVD
CVE-2026-96545Medium· 4.4PoC
4d ago

An out-of-bounds heap read flaw was found in GIMP's TIM image loader

An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that causes promotion to an RGBA layer, the file-tim plug-in allocates an undersized row buffer but processes it using the l…

▾ TwilightRed Hat · gimpEPSS 0.18%via NVD
CVE-2026-84502Critical· 9.9
4d ago

A flaw was found in Red Hat Ansible Automation Platform's automation- controller

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the modul…

▾ MidnightRed Hat · automation-controllerEPSS 0.62%via NVD
CVE-2026-84499High· 7.7
4d ago

A flaw was found in Red Hat Ansible Automation Platform's automation- controller

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or workflow job template no…

▾ TwilightRed Hat · automation-controllerEPSS 0.38%via NVD
CVE-2026-84486High· 8.2
4d ago

A flaw was found in Red Hat Ansible Automation Platform's automation- controller

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal task, dependency, and workflow schedulers are configured to allow any user (including unauthenticated clients) a…

▾ TwilightRed Hat · automation-controllerEPSS 0.52%via NVD
CVE-2026-84474Critical· 9.9
4d ago

A flaw was found in Red Hat Ansible Automation Platform's automation- controller

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template …

▾ MidnightRed Hat · automation-controllerEPSS 0.80%via NVD
CVE-2026-76648High· 8.5
4d ago

CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC

CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC. The get() handler (lines 988–991) explicitly guards with request.user.can_access(obj._class_, 'r…

▾ TwilightRed Hat · ansible-automation-platform-27/controller-rhel9EPSS 0.24%via NVD
CVE-2026-71465Low· 3.1
4d ago

RunAdHocCommand.build_args() appends limit as bare positional (args.append(limit)) instead of using args.extend(['-l', limit]) like RunJob

RunAdHocCommand.build_args() appends limit as bare positional (args.append(limit)) instead of using args.extend(['-l', limit]) like RunJob. A limit beginning with - is parsed as an ansible CLI op…

▾ SunlitRed Hat · automation-controllerEPSS 0.21%via NVD
CVE-2026-71464Low· 3.1
4d ago

LaunchConfigurationBaseSerializer.scm_branch has no validate_scm_branch() leading-dash check, unlike Project/JobTemplate/JobLaunch serializers

LaunchConfigurationBaseSerializer.scm_branch has no validate_scm_branch() leading-dash check, unlike Project/JobTemplate/JobLaunch serializers. Schedule and WFJT Node accept --upload-pack=/bin/id…

▾ SunlitRed Hat · automation-controllerEPSS 0.21%via NVD
CVE-2026-71463Low· 2.7
4d ago

Notification template Jinja AST whitelist only inspects static Getattr nodes

Notification template Jinja AST whitelist only inspects static Getattr nodes. Dynamic subscripts (job['job'+'_env']) and {% if job.id > 100 %} conditional gating bypass both the AST check and the…

▾ SunlitRed Hat · automation-controllerEPSS 0.27%via NVD
CVE-2026-71462Medium· 4.1
4d ago

StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. 200 vs 400 response reveals existence of arbitrary absolute paths on the controller-web pod

StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. 200 vs 400 response reveals existence of arbitrary absolute paths on the controller-web pod. Tenan…

▾ SunlitRed Hat · automation-controllerEPSS 0.26%via NVD
CVE-2026-71461Medium· 4.3
4d ago

HostList.list() catches bare Exception and returns str(e) verbatim

HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated user triggers Django FieldError (leaking complete Host model relation graph including intern…

▾ SunlitRed Hat · ansible-automation-platform-27/controller-rhel9EPSS 0.21%via NVD
CVE-2026-71460Medium· 4.3
4d ago

/api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_id, sku, support_level, instance counts) returned to any authenticated user

/api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_id, sku, support_level, instance counts) returned to any authenticated user. The superuse…

▾ SunlitRed Hat · automation-controllerEPSS 0.22%via NVD
CVE-2026-71459Medium· 5.0
4d ago

JobJobEventsChildrenSummary view has no model/parent_model. ModelAccessPermission.check_get_permissions() falls through (returns True) for any authenticated user

JobJobEventsChildrenSummary view has no model/parent_model. ModelAccessPermission.check_get_permissions() falls through (returns True) for any authenticated user. The view uses raw get_object_or_…

▾ SunlitRed Hat · automation-controllerEPSS 0.28%via NVD
CVE-2026-71458Medium· 5.0
4d ago

URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before RBAC

URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before RBAC. The 403→404 shim only rewrites 403 responses, leaving the pk=0 miss path with a different 404 de…

▾ SunlitRed Hat · automation-controllerEPSS 0.30%via NVD
CVE-2026-96541High· 7.5PoC
4d ago

A denial-of-service flaw was found in gnome-remote-desktop

A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authenticatio…

▾ MidnightRed Hat · gnome-remote-desktopEPSS 0.79%via NVD
CVE-2026-88840Medium· 5.3
4d ago

BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.

BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.

▾ SunlitRed Hat · busyboxEPSS 0.21%via NVD
CVE-2026-88839Medium· 6.7
4d ago

BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.

BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.

▾ SunlitRed Hat · busybox-mainEPSS 0.12%via NVD
Red Hat vulnerabilities (CVEs) — page 2 · VulnSea