VulnSea

Red Hat has 1,289 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1042 in the last 90 days against 125 in the 90 before. The busiest recent month was September 2026 with 642. The median CVSS is 7.0 (high), with 57 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (97) and CWE-825 (89). Most affected products: Red Hat Enterprise Linux 9 (212), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
—(1)
Last 90 days
1042 prev 125

Products

  • Red Hat Enterprise Linux 9 212
  • Red Hat OpenShift Container Platform 4 95
  • Red Hat Enterprise Linux 10 62
  • Linux 57
  • Red Hat OpenShift AI (RHOAI) 45
  • Red Hat Enterprise Linux BaseOS (v. 10) 36
1289
Total CVEs
57
Critical
1
CISA KEV
1
Exploited

Red Hat vulnerabilities

CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.

1289 CVEsRSS

CVE-2026-55685Medium· 6.5
2mo ago

react-router: @remix-run/server-runtime: React Router: Denial of Service via unauthenticated manifest endpoint requests (CVE-2026-55685)

A flaw was found in React Router. An unauthenticated attacker can send targeted requests to the manifest endpoint, leading to a denial of service (DoS). This can put a heavy load on the server, significantly slowing down response times and…

▾ SunlitRed Hat · Red Hat OpenShift AI 3.4EPSS 0.71%via CSAF
CVE-2026-45623High· 7.5
2mo ago

postcss: PostCSS: Information disclosure and denial of service via crafted CSS input (CVE-2026-45623)

A flaw was found in PostCSS, a tool that processes CSS files. An attacker who provides specially crafted CSS input containing a malicious source map comment can cause the system to read arbitrary files from the local filesystem. This can l…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.61%via CSAF
CVE-2026-64530High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation engine (e.g

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle tcf_classify() can return TC_ACT_CONSUMED while the skb is held by the defragmentation engine (e.g. act…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS E4S (v.9.2)EPSS 0.74%via NVD
CVE-2026-66373High· 7.5
2mo ago

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting…

Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 9)EPSS 0.87%via NVD
CVE-2026-64385Critical· 9.8⚖ disputed
2mo ago

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() replay A response-bearing attempt can return a replayable error and free its response buffer

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_ioctl_init() fails b…

▾ MidnightRed Hat · Red Hat Enterprise Linux 9EPSS 0.46%via NVD
CVE-2026-64384Critical· 9.8⚖ disputed
2mo ago

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error and free its response buffer

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_notify_init() fails be…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.46%via NVD
CVE-2026-64382High· 8.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_open() replay A response-bearing attempt can return a replayable error and free its response buffer

In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_open() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_open_init() fails bef…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.35%via NVD
CVE-2026-64368High· 8.1⚖ disputed
2mo ago

In the Linux kernel, the following vulnerability has been resolved: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled When init (zeroing) on allocation is requested, for kmalloc() we generally have to zero the …

In the Linux kernel, the following vulnerability has been resolved: mm/slab: do not limit zeroing to orig_size when only red zoning is enabled When init (zeroing) on allocation is requested, for kmalloc() we generally have to zero the …

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS E4S (v.9.4)EPSS 0.42%via NVD
CVE-2026-64320Critical· 9.1⚖ disputed
2mo ago

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page nvmet_execute_disc_get_log_page() validates only the dword alignment of the host-supplied Log Pag…

In the Linux kernel, the following vulnerability has been resolved: nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page nvmet_execute_disc_get_log_page() validates only the dword alignment of the host-supplied Log Pag…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.75%via NVD
CVE-2026-64319Critical· 9.1⚖ disputed
2mo ago

In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds against transfer length nvmet_auth_reply() accesses the variable-length rval[] array using attacker-controlled hl (ha…

In the Linux kernel, the following vulnerability has been resolved: nvmet-auth: validate reply message payload bounds against transfer length nvmet_auth_reply() accesses the variable-length rval[] array using attacker-controlled hl (ha…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS (v. 9)EPSS 0.52%via NVD
CVE-2026-64304High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - validate RSA CRT component lengths The generic RSA key parser (rsa_helper.c) bounds each CRT component (p, q, dp, dq, qinv) by the modulus size n_sz, but…

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - validate RSA CRT component lengths The generic RSA key parser (rsa_helper.c) bounds each CRT component (p, q, dp, dq, qinv) by the modulus size n_sz, but…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.17%via NVD
CVE-2026-64300High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: perf/aux: Fix page UAF in map_range() map_range() reads rb->aux_pages[], rb->aux_nr_pages and rb->aux_pgoff via perf_mmap_to_page() while holding only event->mmap_mute…

In the Linux kernel, the following vulnerability has been resolved: perf/aux: Fix page UAF in map_range() map_range() reads rb->aux_pages[], rb->aux_nr_pages and rb->aux_pgoff via perf_mmap_to_page() while holding only event->mmap_mute…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.18%via NVD
CVE-2026-64287High· 8.2
2mo ago

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU flush_hyp_vcpu() copies the host vGIC state into the hyp's private vCPU on every run

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU flush_hyp_vcpu() copies the host vGIC state into the hyp's private vCPU on every run. The vGIC list register…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 9)EPSS 0.18%via NVD
CVE-2026-64277High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count rmi_f3a_initialize() takes the GPIO count from the device query register (f3a->gpio_count = buf & RMI_F3…

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count rmi_f3a_initialize() takes the GPIO count from the device query register (f3a->gpio_count = buf & RMI_F3…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.17%via NVD
CVE-2026-64276High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count rmi_f30_map_gpios() allocates gpioled_key_map with min(gpioled_count, TRACKSTICK_RANGE_END) == at mo…

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count rmi_f30_map_gpios() allocates gpioled_key_map with min(gpioled_count, TRACKSTICK_RANGE_END) == at mo…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.17%via NVD
CVE-2026-64268Critical· 9.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each inbound Read Response DDP segment at…

In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: bound Read Response placement to the RREAD length In drivers/infiniband/sw/siw/siw_qp_rx.c, siw_proc_rresp() places each inbound Read Response DDP segment at…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS (v. 9)EPSS 0.71%via NVD
CVE-2026-64265High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req When fuse_resend() moves a request from fpq->processing back to fiq->pending, it sets FR_PENDING and …

In the Linux kernel, the following vulnerability has been resolved: fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req When fuse_resend() moves a request from fpq->processing back to fiq->pending, it sets FR_PENDING and …

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.17%via NVD
CVE-2026-16730Medium· 5.5
2mo ago

A flaw was found in dbus-broker

A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are handled as fatal failures, causing the broker to exit. A local attacker who can open ma…

▾ SunlitRed Hat · dbus-brokerEPSS 0.11%via NVD
CVE-2026-66007Medium· 6.5
2mo ago

datasets: Datasets: Information disclosure via path traversal vulnerability (CVE-2026-66007)

A flaw was found in datasets. This path traversal vulnerability allows a remote attacker to read arbitrary local files. By providing specially crafted file names in the metadata, an attacker can trick the system into including sensitive lo…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.79%via CSAF
CVE-2025-71408High· 7.0
2mo ago

nltk: NLTK: Arbitrary Code Execution via Eval Injection in Collocations Module (CVE-2025-71408)

A flaw was found in NLTK (Natural Language Toolkit). This eval injection vulnerability in the `nltk.collocations` module allows a local attacker to execute arbitrary Python code. By manipulating command-line arguments when `collocations.py…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.27%via CSAF
CVE-2026-17107High· 8.5
2mo ago

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE)

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests wit…

▾ TwilightRed Hat · multicluster-engine/cluster-proxy-rhel9EPSS 0.57%via NVD
CVE-2026-64255High· 8.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers Three BA session handlers use ffs(ba_data->sta_mask) - 1 to derive a station ID without check…

In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers Three BA session handlers use ffs(ba_data->sta_mask) - 1 to derive a station ID without check…

▾ TwilightRed Hat · Red Hat Enterprise Linux BaseOS (v. 10)EPSS 0.22%via NVD
CVE-2026-64218High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: fix report_work leak on backbone_gw purge batadv_bla_purge_backbone_gw() removes stale backbone gateway entries, but fails to properly handle their as…

In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: fix report_work leak on backbone_gw purge batadv_bla_purge_backbone_gw() removes stale backbone gateway entries, but fails to properly handle their as…

▾ TwilightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.18%via NVD
CVE-2026-64217High· 7.8
2mo ago

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix overrun check in netfs_extract_user_iter() Fix netfs_extract_user_iter() so that if iov_iter_extract_pages() overfills pages[], then those pages don't get i…

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix overrun check in netfs_extract_user_iter() Fix netfs_extract_user_iter() so that if iov_iter_extract_pages() overfills pages[], then those pages don't get i…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.13%via NVD
CVE-2026-16745High· 8.8
2mo ago

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI)

A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor within the cluster can bypass authentication and impersonate any user by providing an arbit…

▾ TwilightRed Hat · rhoai/odh-dashboard-rhel9EPSS 0.45%via NVD
CVE-2026-44210Critical· 9.9
2mo ago

kata-containers: Kata Containers: Privilege escalation and information disclosure via command-line argument injection (CVE-2026-44210)

A flaw was found in Kata Containers, an open-source project that provides lightweight virtual machines (VMs) for containers. A user with privileges to create pods can inject malicious command-line arguments into the virtiofsd process, whic…

▾ MidnightRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.59%via CSAF
CVE-2026-64600High· 7.8PoC
2mo ago

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapp…

In the Linux kernel, the following vulnerability has been resolved: xfs: resample the data fork mapping after cycling ILOCK xfs_reflink_fill_{cow_hole,delalloc} are both presented with an inode, a data fork mapping, and a cow fork mapp…

▾ MidnightRed Hat · Red Hat Enterprise Linux BaseOS E4S (v.9.4)EPSS 0.16%via NVD
CVE-2026-14257High· 7.5
2mo ago

brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257)

A flaw was found in brace-expansion. A remote attacker can exploit this vulnerability by providing specially crafted input to the expand() function, which can lead to excessive memory consumption. This can cause a denial of service (DoS) b…

▾ TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 8)EPSS 0.64%via CSAF
CVE-2026-25800High· 7.5
2mo ago

quinn: Quinn: Remote memory exhaustion via malformed QUIC stream fragments (CVE-2026-25800)

A flaw was found in Quinn, a Rust implementation of the QUIC transport protocol. A remote attacker can exploit this vulnerability by sending specially crafted QUIC stream fragments with many gaps. This can lead to high buffer overhead in t…

▾ TwilightRed Hat · quinn-protoEPSS 0.61%via CSAF
CVE-2026-16517Low· 2.9
2mo ago

A signed integer overflow vulnerability was found in libarchive's ZIP writer

A signed integer overflow vulnerability was found in libarchive's ZIP writer. In the archive_write_zip_header function in archive_write_set_format_zip.c, when ZIP encryption is enabled and the entry file size is close to INT64_MAX, the a…

▾ SunlitRed Hat · libarchiveEPSS 0.08%via NVD
Red Hat vulnerabilities (CVEs) — page 32 · VulnSea