VulnSea

Red Hat has 1,289 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1042 in the last 90 days against 125 in the 90 before. The busiest recent month was September 2026 with 642. The median CVSS is 7.0 (high), with 57 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (97) and CWE-825 (89). Most affected products: Red Hat Enterprise Linux 9 (212), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
—(1)
Last 90 days
1042 prev 125

Products

  • Red Hat Enterprise Linux 9 212
  • Red Hat OpenShift Container Platform 4 95
  • Red Hat Enterprise Linux 10 62
  • Linux 57
  • Red Hat OpenShift AI (RHOAI) 45
  • Red Hat Enterprise Linux BaseOS (v. 10) 36
1289
Total CVEs
57
Critical
1
CISA KEV
1
Exploited

Red Hat vulnerabilities

CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.

1289 CVEsRSS

CVE-2026-49478High· 8.7⚖ disputed
1mo ago

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Versions through 1.8.5 improperly follow cross-host redirects and attach Kubernetes ServiceAccount tokens during OIDC discover…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.28%via NVD
CVE-2026-48702High· 7.5
1mo ago

Rekor is a software supply chain transparency log

Rekor is a software supply chain transparency log. Starting in version 0.3.0 and prior to version 1.5.2, the `Package.Unmarshal()` function in `pkg/types/alpine/apk.go` decompresses the signature and control gzip members of an APK file i…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 0.46%via NVD
CVE-2026-71471Critical· 9.0
1mo ago

Acm-search-v2-rhel9: search-v2-operator: hub search cr collector.imageoverride propagated to every spoke as arbitrary container image

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search Custom Resource (CR), could exploit a vulnerability in the `Collector.ImageOverride` fie…

▾ MidnightRed Hat · rhacm2/acm-search-v2-rhel9EPSS 1.2%via CVEORG
CVE-2026-64927Medium· 6.4
1mo ago

A flaw was found in the multicloud-operators-channel component

A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the system handles sensitive information, known as Secrets, across different parts of the system…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.11EPSS 0.33%via NVD
CVE-2026-73269Critical· 9.9
1mo ago

A flaw was found in the cluster-curator-controller component

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, can trigger the creation of a cluster-scoped ClusterRoleBinding. This allows the user to…

▾ MidnightRed Hat · multicluster-engine/cluster-curator-controller-rhel9EPSS 0.56%via NVD
CVE-2026-73268Critical· 9.9
1mo ago

A flaw was found in the cluster-curator-controller component of multicluster engine (MCE)

A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the Cre…

▾ MidnightRed Hat · multicluster-engine/cluster-curator-controller-rhel9EPSS 0.88%via NVD
CVE-2026-13622High· 8.8
1mo ago

A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy

A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symli…

▾ TwilightRed Hat · container-native-virtualization/virt-handlerEPSS 0.20%via NVD
CVE-2026-19130Medium· 5.8
1mo ago

A flaw was found in the provider-credential-controller component of multicluster-engine (MCE)

A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub cluster, and knowledge of a prior credential value, could exploit an authorization bypass vul…

▾ SunlitRed Hat · multicluster-engine/provider-credential-controller-rhel9EPSS 0.40%via NVD
CVE-2026-73501Critical· 9.1
1mo ago

kin-openapi is a Go project for handling OpenAPI files

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces a nil AuthenticationFunc with NoopAuthenticationFunc, which returns nil without …

▾ MidnightRed Hat · Red Hat Edge Manager 1EPSS 0.59%via NVD
CVE-2026-73500High· 7.5
1mo ago

etcd is a distributed key-value store for the data of a distributed system

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can reach an etcd TLS listener can open many TCP connections and never send a ClientHello. In…

▾ TwilightRed Hat · Red Hat Trusted Artifact SignerEPSS 0.70%via NVD
CVE-2026-73415High· 8.0
1mo ago

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4.6.2, in packages/imageviewer/src/widget.ts, JupyterLab's ImageViewer uses URL.createObj…

▾ TwilightRed Hat · Red Hat OpenShift AI 2.25EPSS 0.74%via NVD
CVE-2026-14180Medium· 5.3
1mo ago

A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding

A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the …

▾ SunlitRed Hat · eap8-activemq-artemisEPSS 1.0%via NVD
CVE-2026-15567High· 7.5
1mo ago

A flaw was found in Wildfly

A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-controlled length field without bounds checking and attempts to allocate a byte array of that …

▾ TwilightRed Hat · org.jboss.eap/wildfly-iiop-openjdkEPSS 0.55%via NVD
CVE-2026-15565High· 7.5
1mo ago

A flaw was found in Undertow

A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class that has any @OnMessage method. This allows an attacker to cause Denial of Service attack …

▾ TwilightRed Hat · io.undertow/undertow-websockets-jsrEPSS 0.61%via NVD
CVE-2026-15563High· 7.4
1mo ago

A flaw was found in EAP's IIOP

A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.

▾ TwilightRed Hat · org.jboss.eap/wildfly-iiop-openjdkEPSS 0.39%via NVD
CVE-2026-15562High· 7.5
1mo ago

A flaw was found in EAP's jboss-remoting

A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-remoting handshake can cause OOM errors that degrade requests server-wide, leading to den…

▾ TwilightRed Hat · org.jboss.remoting/jboss-remotingEPSS 0.55%via NVD
CVE-2026-15561High· 7.5
1mo ago

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthenticated connection to drive the JVM to an OutOfMemory error, stopping all deployments on the…

▾ TwilightRed Hat · io.undertow/undertow-coreEPSS 0.46%via NVD
CVE-2026-15556High· 8.1
1mo ago

A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the prot…

A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow an attacker to forge a SAML response and auth as any principal with any roles on the prot…

▾ TwilightRed Hat · org.picketlink/picketlink-federationEPSS 0.24%via NVD
CVE-2026-15555High· 8.8
1mo ago

A flaw was found in JBoss marshalling

A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on …

▾ TwilightRed Hat · org.jboss.eap/wildfly-clustering-infinispan-marshallingEPSS 0.32%via NVD
CVE-2026-15554High· 7.4
1mo ago

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentica…

▾ TwilightRed Hat · io.undertow/undertow-coreEPSS 0.35%via NVD
CVE-2026-15560High· 8.1
1mo ago

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in…

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in…

▾ TwilightRed Hat · org.jboss.eap/wildfly-iiop-openjdkEPSS 0.57%via NVD
CVE-2026-10579Critical· 9.8
1mo ago

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any role. This could l…

▾ MidnightRed Hat · org.picketlink/picketlink-federationEPSS 0.32%via NVD
CVE-2026-72693High· 7.8
1mo ago

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `kbrequest`/init usage, the ownership test in `authenticate_user()` relies on `stat("/proc…

▾ TwilightRed Hat · kbdEPSS 0.16%via NVD
CVE-2026-73072High· 7.8PoC
1mo ago

Vim is an open source, command line text editor

Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left by set_sal_first(), so a crafted spell file containing an SN_SAL section before an SN_S…

▾ MidnightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.13%via NVD
CVE-2026-73066High· 7.1
1mo ago

Tesseract is an open source OCR engine

Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolv…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.13%via NVD
CVE-2026-19546High· 8.8
1mo ago

A flaw was found in DBI

A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mitigation please reffer to the original https://access.redhat.com/security/cve/cve-2026-19…

▾ TwilightRed Hat · perl-DBIEPSS 0.35%via NVD
CVE-2026-72694High· 7.1
1mo ago

A flaw was found in MRTG

A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can exploit a symbolic link (symlink) following vulnerability. By influencing or pre-placing a s…

▾ TwilightRed Hat · mrtgEPSS 0.17%via NVD
CVE-2026-71468Medium· 5.3
1mo ago

A flaw was found in acm-search-v2-api-rhel9

A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token for all subsequent federated requests until the cache expires. This allows other authent…

▾ SunlitRed Hat · Red Hat Advanced Cluster Management for Kubernetes 2.11EPSS 0.42%via NVD
CVE-2026-73088High· 7.5
1mo ago

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist()…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.66%via NVD
CVE-2026-73089High· 7.5
1mo ago

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools

Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCac…

▾ TwilightRed Hat · Red Hat Enterprise Linux 8EPSS 0.66%via NVD
Red Hat vulnerabilities (CVEs) — page 28 · VulnSea