VulnSea

Red Hat has 1,289 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1047 in the last 90 days against 120 in the 90 before. The busiest recent month was September 2026 with 642. The median CVSS is 7.0 (high), with 57 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (97) and CWE-825 (89). Most affected products: Red Hat Enterprise Linux 9 (212), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
—(1)
Last 90 days
1047 prev 120

Products

  • Red Hat Enterprise Linux 9 212
  • Red Hat OpenShift Container Platform 4 95
  • Red Hat Enterprise Linux 10 62
  • Linux 57
  • Red Hat OpenShift AI (RHOAI) 45
  • Red Hat Enterprise Linux BaseOS (v. 10) 36
1289
Total CVEs
57
Critical
1
CISA KEV
1
Exploited

Red Hat vulnerabilities

CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.

1289 CVEsRSS

CVE-2026-89484Medium· 5.5
2w ago

kernel: lockd: fix NULL dereference on lockowner allocation failure (CVE-2026-89484)

A flaw was found in the Linux kernel's `lockd` component. This vulnerability occurs when the Network Lock Manager (NLM) client attempts to initialize file lock operations without successfully allocating a lockowner. This can lead to a NULL…

▾ SunlitRed Hat · Red Hat Enterprise Linux 9EPSS 0.21%via CSAF
CVE-2026-89468Medium· 5.5
2w ago

kernel: power: supply: lp8788-charger: fix use-after-free on remove (CVE-2026-89468)

A flaw was found in the Linux kernel's lp8788-charger component. During the removal of the lp8788-charger, a race condition can occur where work can be queued and executed after the associated memory has been freed. This use-after-free vul…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.21%via CSAF
CVE-2026-89467Medium· 5.5
2w ago

kernel: power: supply: qcom_battmgr: fix use-after-free (CVE-2026-89467)

A flaw was found in the Linux kernel's `qcom_battmgr` component. This flaw is a use-after-free vulnerability that occurs because the `qcom_battmgr_pdr_notify()` function can queue `enable_work` even after the associated `battmgr` object ha…

▾ SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.21%via CSAF
CVE-2026-89462Medium· 5.5
2w ago

kernel: power: supply: max17040: propagate register read errors (CVE-2026-89462)

A flaw was found in the Linux kernel's power supply subsystem, specifically within the max17040 driver. This vulnerability occurs when the `max17040_get_vcell()` and `max17040_get_soc()` functions fail to properly handle errors returned by…

▾ SunlitRed Hat · LinuxEPSS 0.21%via CSAF
CVE-2026-77159Medium· 5.5PoC
2w ago

A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function

A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepareHost() function. The function uses a path-based chown() on the swtpm logfile without checking for symbolic links. A local attacker with access to the swtpm account can…

▾ TwilightRed Hat · libvirtEPSS 0.16%via NVD
CVE-2026-88914Medium· 4.4
2w ago

A flaw was found in GStreamer's gst-plugins-good isomp4 plugin

A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a bounds check in th…

▾ SunlitRed Hat · gstreamer1-plugins-goodEPSS 0.18%via NVD
CVE-2026-89298Medium· 4.9
2w ago

A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution

A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management solution. The issue occurs when a user with the view-clients role accesses the client registration endpoint to retriev…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.41%via NVD
CVE-2026-87859Medium· 5.3
2w ago

morgan is an HTTP request logger middleware for Node.js

morgan is an HTTP request logger middleware for Node.js. In versions before 1.12.1, its escapeLogField() function does not escape the double quote character, which delimits the quoted fields of the Apache combined log format that morgan …

▾ SunlitRed Hat · Red Hat Enterprise Linux 10EPSS 0.41%via NVD
CVE-2026-88763Medium· 5.9
2w ago

A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services

A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message …

▾ SunlitRed Hat · skupper-routerEPSS 0.41%via NVD
CVE-2026-88265Medium· 5.6
2w ago

A flaw was found in crun

A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to container stdio, then change that file's ownership. Affected versions are crun 1.29.1 and earlier. Default configura…

▾ SunlitRed Hat · crunEPSS 0.15%via NVD
CVE-2026-89046High· 8.2PoC
2w ago

zstd-jni: zstd-jni: Information disclosure or denial of service via out-of-bounds read (CVE-2026-89046)

A flaw was found in zstd-jni. This out-of-bounds read vulnerability in the Zstd.getFrameContentSize function occurs because it fails to validate negative srcPosition arguments. A remote attacker can supply negative offset values, bypassing…

▾ MidnightRed Hat · Red Hat Ceph Storage 9EPSS 0.65%via CSAF
CVE-2026-87933High· 8.6PoC
2w ago

cJSON: cJSON: Memory corruption via use after free in cJSONUtils_MergePatch (CVE-2026-87933)

A flaw was found in DaveGamble cJSON. The `cJSONUtils_MergePatch` function in `cJSON_Utils.c` is vulnerable to a use-after-free error. A remote attacker could exploit this memory corruption vulnerability, potentially leading to information…

▾ MidnightRed Hat · Red Hat Satellite 6EPSS 0.53%via CSAF
CVE-2026-84042High· 7.8
2w ago

A flaw was found in crun

A flaw was found in crun. When crun is built with libkrun and a container is started rootful with passt networking (krun.use_passt), crun can execute attacker-controlled payload from the container image with host root privileges. The iss…

▾ TwilightRed Hat · crunEPSS 0.14%via NVD
CVE-2026-88859Medium· 6.3
2w ago

A flaw was found in Evolution

A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler in…

▾ SunlitRed Hat · evolutionEPSS 0.53%via NVD
CVE-2026-84828Medium· 6.5
2w ago

A flaw was found in PCS (Pacemaker Configuration System)

A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can exploit the 'pcs host auth --token' command to read the contents of arbitrary files on the filesystem, provided the fi…

▾ SunlitRed Hat · pcsEPSS 0.14%via NVD
CVE-2026-88770Medium· 6.5
2w ago

A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution

A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The issue occurs because the token redemption process fails to check if a user account is currently locked due to brute-forc…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.35%via NVD
CVE-2026-87875Medium· 4.3PoC
2w ago

Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-length bound

The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backen…

▾ TwilightRed Hat · cups-mainEPSS 0.39%via CVEORG
CVE-2026-87795High· 8.2PoC
2w ago

com.github.luben/zstd-jni: zstd-jni: Out-of-bounds read in ZstdDictCompress constructor leads to denial of service (CVE-2026-87795)

A flaw was found in zstd-jni. This vulnerability occurs due to insufficient validation of offset and length parameters within the `ZstdDictCompress` constructor. An attacker can exploit this by providing untrusted values, leading to an out…

▾ MidnightRed Hat · Red Hat Ceph Storage 9EPSS 0.63%via CSAF
CVE-2026-87872Medium· 6.8
2w ago

A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection

A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re…

▾ SunlitRed Hat · ansible-collection-community-generalEPSS 0.14%via NVD
CVE-2026-87853High· 7.5
2w ago

A flaw was found in SSSD's IdP authentication provider

A flaw was found in SSSD's IdP authentication provider. The eval_access_token_buf() function compares the OIDC subject identifier using strncmp() with the authenticated user's identifier length, performing a prefix comparison instead of …

▾ TwilightRed Hat · sssdEPSS 0.48%via NVD
CVE-2026-18147High· 8.1
2w ago

A flaw was found in FreeIPA

A flaw was found in FreeIPA. An unauthenticated remote attacker could exploit a DOM Cross-Site Scripting (XSS) vulnerability in the FreeIPA/IdM Web UI password reset page. By enticing a victim to click a specially crafted link and comple…

▾ TwilightRed Hat · ipaEPSS 0.33%via NVD
CVE-2026-87876Low· 3.0PoC
2w ago

Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certai…

Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certai…

▾ TwilightRed Hat · cups-mainEPSS 0.33%via NVD
CVE-2026-87874High· 8.1
2w ago

A flaw was found in the memcached cache plugin of the community.general Ansible collection

A flaw was found in the memcached cache plugin of the community.general Ansible collection. Although its documentation states that records are stored in JSON format, the plugin performs no explicit serialization and relies on python-memc…

▾ TwilightRed Hat · ansible-collection-community-generalEPSS 0.72%via NVD
CVE-2026-87766High· 8.8
2w ago

A flaw was found in bubblewrap

A flaw was found in bubblewrap. During sandbox setup, creating files or directories under the new root can follow a parent symlink onto the host via /oldroot, writing attacker-chosen paths outside the sandbox as the launching user. This …

▾ TwilightRed Hat · bubblewrapEPSS 0.15%via NVD
CVE-2026-19729Medium· 4.9
2w ago

A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak

A flaw was found in the key provider component of the keycloak-services library, which is the core engine for the Red Hat Build of Keycloak. The issue occurs because a previous fix for path probing was incomplete, allowing a realm admini…

▾ SunlitRed Hat · keycloak-rhel9-containerEPSS 0.48%via NVD
CVE-2026-86564Low· 3.3
2w ago

A flaw was found in DPDK lib/vhost

A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.

▾ SunlitRed Hat · openvswitch3.5EPSS 0.14%via NVD
CVE-2026-18090Medium· 6.1
2w ago

A flaw was found in gdk-pixbuf

A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon…

▾ SunlitRed Hat · gdk-pixbuf2EPSS 0.17%via NVD
CVE-2026-85630Medium· 6.1
2w ago

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than lit…

HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field labels where some attributes are built from data rather than lit…

▾ SunlitRed Hat · HTML-FormHandlerEPSS 0.24%via NVD
CVE-2026-85485Medium· 6.1⚖ disputed
2w ago

HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup

HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers splice each error string straight into the surrounding markup. Version 0…

▾ SunlitRed Hat · HTML-FormHandlerEPSS 0.26%via NVD
CVE-2026-85484Medium· 6.1
2w ago

HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping. The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Sele…

HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping. The Select, RadioGroup, CheckboxGroup and HorizCheckboxGroup widgets render a group label unescaped, Sele…

▾ SunlitRed Hat · HTML-FormHandlerEPSS 0.33%via NVD
Red Hat vulnerabilities (CVEs) — page 20 · VulnSea