VulnSea

Red Hat has 1,283 CVEs on record between 2020 and 2026. Disclosure cadence is accelerating: 1041 in the last 90 days against 120 in the 90 before. The busiest recent month was September 2026 with 636. The median CVSS is 7.0 (high), with 58 rated critical. 0% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-125 (97) and CWE-825 (89). Most affected products: Red Hat Enterprise Linux 9 (212), Red Hat OpenShift Container Platform 4 (95), Red Hat Enterprise Linux 10 (62).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.0
Publish → KEV
—(1)
Last 90 days
1041 prev 120

Products

  • Red Hat Enterprise Linux 9 212
  • Red Hat OpenShift Container Platform 4 95
  • Red Hat Enterprise Linux 10 62
  • Linux 57
  • Red Hat OpenShift AI (RHOAI) 45
  • Red Hat Enterprise Linux BaseOS (v. 10) 36
1283
Total CVEs
58
Critical
1
CISA KEV
1
Exploited

Red Hat vulnerabilities

CVEs affecting Red Hat, newest first. Open any entry for full detail, references, and exploit status.

1283 CVEsRSS

CVE-2026-81829Medium· 5.3
1w ago

A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers

A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch UR…

▾ SunlitRed Hat · exploit-intelligence/agent-client-rhel9EPSS 0.58%via NVD
CVE-2026-92904Medium· 4.3
1w ago

A flaw was found in the foreman_remote_execution plugin's template invocations controller

A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller's view_job_invocations permission filt…

▾ SunlitRed Hat · rubygem-foreman_remote_executionEPSS 0.34%via NVD
CVE-2026-92925High· 7.1
1w ago

A flaw was found in Redis community

A flaw was found in Redis community. The cluster bus packet parser, responsible for handling PING, PONG, and MEET packets, fails to properly validate string-carrying extensions for null-termination. This oversight allows a remote attacke…

▾ TwilightRed Hat · redis:7EPSS 0.57%via NVD
CVE-2026-92893Medium· 4.3
1w ago

A flaw was found in the foreman_ansible plugin's Ansible inventory API

A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an unscoped Host.where call that does not enforce the search filter associated with the caller's view_hosts permission. An…

▾ SunlitRed Hat · rubygem-foreman_ansibleEPSS 0.28%via NVD
CVE-2026-92894Medium· 4.3
1w ago

A flaw was found in the foreman_ansible plugin's Ansible override values API

A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target LookupValue record by ID without verifying it belongs to an AnsibleVariable the caller is authorized to edit. An authent…

▾ SunlitRed Hat · rubygem-foreman_ansibleEPSS 0.26%via NVD
CVE-2026-86320High· 7.8PoC
1w ago

A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true

A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. An attacker who can provide a malicious source containing a Git post-applypatch hook can cause the hook to execute on…

▾ MidnightRed Hat · flatpak-builderEPSS 0.22%via NVD
CVE-2026-85469High· 8.0
1w ago

A flaw was found in quay-builder-qemu

A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docker-manifest-action` used in the release workflow, which is pinned to a mutable branch. This allows the attacker to inj…

▾ TwilightRed Hat · quay/quay-builder-qemu-rhcos-rhel8EPSS 0.52%via NVD
CVE-2026-42784High· 7.4
1w ago

A flaw was found in sequoia-openpgp

A flaw was found in sequoia-openpgp. The library incorrectly infers key flags for older certificates when a key flags subpacket is missing, leading to a discrepancy in how key capabilities are viewed. This key flag confusion allows an at…

▾ TwilightRed Hat · rust-podman-sequoia-mainEPSS 0.20%via NVD
CVE-2026-92615Medium· 6.6
1w ago

A flaw was found in flightctl

A flaw was found in flightctl. The configureRepoHTTPSClient() function in the device-render worker builds a per-repository tls.Config (which may include InsecureSkipVerify, a custom CA bundle, or tenant-supplied mTLS client certificates)…

▾ SunlitRed Hat · flightctlEPSS 0.15%via NVD
CVE-2026-17526High· 7.2
1w ago

Keycloak is an open-source identity and access management solution

Keycloak is an open-source identity and access management solution. A vulnerability was discovered where a user with the impersonation role can impersonate a realm administrator. This allows the attacker to gain full administrative contr…

▾ TwilightRed Hat · keycloak-rhel9-containerEPSS 0.45%via NVD
CVE-2026-19607Medium· 5.3
1w ago

A flaw was found in the first-broker-login flow of the keycloak-services component

A flaw was found in the first-broker-login flow of the keycloak-services component. This component handles the initial authentication and account linking when a user logs in via an external identity provider. The issue allows an attacker…

▾ SunlitRed Hat · keycloak-rhel9-containerEPSS 0.51%via NVD
CVE-2026-18212High· 7.5
1w ago

A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution

A flaw was found in the SAML Redirect Binding implementation of Keycloak, an open-source identity and access management solution. The issue occurs because the custom DEFLATE compression and decompression helpers fail to release native zl…

▾ TwilightRed Hat · keycloak-rhel9-containerEPSS 0.52%via NVD
CVE-2026-74909High· 8.1
1w ago

Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies

Keycloak provides a policy enforcer to protect applications by matching incoming web requests against defined security policies. A flaw was found where the enforcer fails to correctly normalize web addresses that contain special encoded …

▾ TwilightRed Hat · rhbk/keycloak-operator-bundleEPSS 0.85%via NVD
CVE-2026-79651High· 7.5
1w ago

A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak

A flaw was found in the theme localization endpoints of the keycloak-services component, which is the core service responsible for authentication flows and theme management in Keycloak. The issue occurs because the system accepts arbitra…

▾ TwilightRed Hat · keycloak-rhel9-containerEPSS 0.81%via NVD
CVE-2026-92091Medium· 5.9PoC
1w ago

A flaw was found in jwcrypto

A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and the length of key_ops is not bounded. A remote, unauthenticated attacke…

▾ TwilightRed Hat · ansible-automation-platform-24/controller-rhel8EPSS 0.66%via NVD
CVE-2026-92358Medium· 6.4
1w ago

A flaw was found in the first broker login flow of Keycloak

A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request from a different browser, a temporary proof is created to validate the link. However, this proof is not properly cleared after t…

▾ SunlitRed Hat · keycloak/rhbk-openshift-rhel9EPSS 0.27%via NVD
CVE-2025-11395Medium· 5.5
1w ago

A flaw was found in Podman

A flaw was found in Podman. If an attacker can pass a crafted tar archive to the `podman load` command, they can create files on the host machine with the privileges of the user running Podman.

▾ SunlitRed Hat · buildahEPSS 0.24%via NVD
CVE-2026-85234High· 7.5
1w ago

A flaw was found in tftp-hpa

A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a non-empty custom error message, it can pass invalid match offsets to the `genmatchstring()` function. This leads to ou…

▾ TwilightRed Hat · tftpEPSS 0.78%via NVD
CVE-2026-79699Medium· 4.4
1w ago

A flaw was found in the containers/storage library

A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. victim/.wh.) can cause the extraction destination directory to be replaced with an arbitrary file when processed by st…

▾ SunlitRed Hat · ansible-automation-platform-24/eda-controller-rhel8EPSS 0.17%via NVD
CVE-2026-79705Medium· 4.5
1w ago

A flaw was found in the buildah/copier Go package

A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar archive containing malicious symlinks can escape the target extraction directory and create files outside the intended de…

▾ SunlitRed Hat · ansible-automation-platform-24/eda-controller-rhel8EPSS 0.38%via NVD
CVE-2026-85013High· 7.3PoC
1w ago

A flaw was found in environment-modules

A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `…

▾ MidnightRed Hat · environment-modules-mainEPSS 0.22%via NVD
CVE-2026-91926Low· 3.7
1w ago

A flaw was found in gss-ntlmssp

A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. The parser allocates memory for each string value but does not …

▾ SunlitRed Hat · gssntlmsspEPSS 0.37%via NVD
CVE-2026-91786Medium· 6.1
1w ago

A flaw was found in GNOME Shell

A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to validate the icon's declared dimensions against the actual data buffer size. A malicious or compromised remote search pro…

▾ SunlitRed Hat · gnome-shellEPSS 0.17%via NVD
CVE-2026-75092High· 7.3
1w ago

A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository)

A privilege escalation flaw was found in the scan_mysql actor of leapp-upgrade-el9toel10 (provided by leapp-repository). During RHEL 9 to RHEL 10 upgrades, the actor runs: mysqld --validate-config --log-error-verbosity=2 directly as root…

▾ TwilightRed Hat · leapp-repositoryEPSS 0.13%via NVD
CVE-2026-81320Medium· 5.5
1w ago

A flaw was found in hawtio-operator

A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log level 1 or higher, the entire Route object — including the TLS private key in PEM format — is serialized to JSON and wri…

▾ SunlitRed Hat · rhbac-4/hawtio-rhel9EPSS 0.19%via NVD
CVE-2026-81303Medium· 6.3
1w ago

A flaw was found in hawtio-operator

A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the tenant-supplied spec.routeHostName value from the Hawtio custom resource directly into the Route spec without valida…

▾ SunlitRed Hat · rhbac-4/hawtio-operator-bundleEPSS 0.49%via NVD
CVE-2026-90815Medium· 6.3PoC
1w ago

A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1

A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function setup_3x3 of the file libavfilter/vf_convolution.c of the component Convolution Filter. Such manipulation leads to out-o…

▾ TwilightRed Hat · FFmpegEPSS 0.42%via NVD
CVE-2026-90816Medium· 4.3PoC
1w ago

A vulnerability was found in FFmpeg 8.0.x

A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial…

▾ TwilightRed Hat · FFmpegEPSS 0.58%via NVD
CVE-2026-90996Medium· 4.0
1w ago

A flaw was found in sssd

A flaw was found in sssd. A local unprivileged user could send a specially crafted request with a zero-length body to the Network Security Services (NSS) responder. This could lead to a denial-of-service condition, causing the NSS respon…

▾ SunlitRed Hat · sssdEPSS 0.16%via NVD
CVE-2026-90995Medium· 5.5
1w ago

A flaw was found in SSSD (System Security Services Daemon)

A flaw was found in SSSD (System Security Services Daemon). A local attacker with privileges to connect to the PAM (Pluggable Authentication Modules) responder socket can send a specially crafted protocol request. If the `pam_app_service…

▾ SunlitRed Hat · sssdEPSS 0.15%via NVD
Red Hat vulnerabilities (CVEs) — page 6 · VulnSea