Skip to content
Threat Feed

Vendor

Red Hat

189 briefs RSS
critical advisory

Unauthenticated SSRF and DoS in OpenShift Console

An unauthenticated vulnerability in the OpenShift console /api/devfile/ endpoints allows remote attackers to perform Server-Side Request Forgery (SSRF) and cause Denial of Service (DoS) via memory exhaustion.

OpenShift vulnerability cloud web-application
1t 1c
medium advisory

Local Arbitrary Code Execution and Denial of Service Vulnerability in Red Hat CloudForms

Red Hat CloudForms contains a local vulnerability that allows an attacker to execute arbitrary code with user-level privileges or trigger a denial-of-service condition.

CloudForms vulnerability local-access red-hat
1t
low advisory

CVE-2026-89059: Denial of Service in RESTEasy IIOImageProvider

An unauthenticated remote attacker can trigger a denial of service in Red Hat RESTEasy by submitting a crafted image that causes excessive memory allocation within the JVM via the IIOImageProvider component.

RESTEasy denial-of-service java
1t 1c
high advisory

Denial of Service Vulnerability in Quarkus WebSockets Next

A vulnerability in quarkus-websockets-next allows a remote attacker to cause a Denial of Service via heap exhaustion by streaming WebSocket messages faster than the application can process them.

Quarkus +1 denial-of-service java application-security web-application security-flaw authorization-bypass
1t 1c updated
low advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux Components

Multiple vulnerabilities in corosync, libevent, and libsoup within Red Hat Enterprise Linux could allow attackers to execute arbitrary code, bypass security controls, disclose data, or cause denial-of-service.

Enterprise Linux +1 vulnerability rhel linux
1t 1c updated
high advisory

Supply Chain Vulnerability in quay-builder-qemu via Mutable GitHub Action

A supply chain vulnerability in quay-builder-qemu allows for remote code execution and credential theft due to the use of a mutable GitHub Action dependency.

quay-builder-qemu supply-chain ci-cd vulnerability
2t 1c
low advisory

CVE-2026-18212 Keycloak Denial of Service via SAML Redirect Binding

An unauthenticated attacker can trigger a denial of service in Keycloak by sending repeated malformed SAML requests that cause native memory exhaustion due to improper zlib memory management.

Keycloak denial-of-service vulnerability
1t 1c
medium advisory

Multiple Denial of Service Vulnerabilities in System Security Services Daemon

Local attackers can exploit multiple vulnerabilities in the System Security Services Daemon (SSSD) to trigger a denial of service condition, impacting authentication and identity management services on Linux systems.

System Security Services Daemon denial-of-service sssd linux authentication
1t
high advisory

Privilege Escalation in leapp-upgrade-el9toel10

A privilege escalation vulnerability (CVE-2026-75092) in the leapp-upgrade-el9toel10 package allows an attacker with mysql OS identity access to execute arbitrary code as root during RHEL upgrade workflows.

leapp-upgrade-el9toel10 vulnerability privilege-escalation linux rhel
1t 1c
high advisory

Information Disclosure Vulnerability in multicluster-observability-addon

A configuration reference vulnerability in the multicluster-observability-addon allows a managed cluster identity to bypass namespace restrictions and exfiltrate sensitive hub-level secrets.

multicluster-observability-addon vulnerability cloud-native kubernetes
1t 1c
low advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux python-cryptography Package

Multiple vulnerabilities in the python-cryptography package for Red Hat Enterprise Linux, including CVE-2024-26130, may allow a remote, unauthenticated attacker to bypass security controls or cause a denial-of-service condition.

Enterprise Linux +1 vulnerability linux cryptography low-severity
1t 1c updated
high advisory

Command Injection in 389 Directory Server Cockpit Console

A command injection vulnerability in the 389 Directory Server Cockpit console allows authenticated users with entry-creation privileges to achieve root-level command execution via crafted LDAP distinguished names.

389 Directory Server cve-2026-19843 command-injection privilege-escalation
2t 1c
high advisory

CVE-2026-86404 Arbitrary Deserialization in Red Hat JBoss EAP

Red Hat JBoss Enterprise Application Platform (EAP) contains a vulnerability in its Artemis component where default deserialization configurations permit arbitrary object deserialization, potentially leading to remote code execution.

JBoss Enterprise Application Platform vulnerability deserialization rce
2t 1c
high advisory

Stack Out-of-Bounds Write in gfs2-utils

A stack-based out-of-bounds write vulnerability in the gfs2_edit utility allows arbitrary code execution via crafted GFS2 filesystem images.

gfs2-utils
1t 1c
high threat

Breeze Comet Targeting Brazilian Financial Systems

Breeze Comet is a financially motivated actor targeting Brazilian payment systems via social engineering, web shell deployment, and custom routing malware to execute fraudulent financial transactions.

JBoss AS Breeze Comet financial-fraud malware lateral-movement
3t 1i
high advisory

RESTEasy XML External Entity Vulnerability in SourceProvider

An XML External Entity (XXE) vulnerability in RESTEasy's SourceProvider allows unauthenticated attackers to perform arbitrary remote file reads via malicious XML input.

RESTEasy web-application xxe vulnerability
1t 1c
high advisory

Remote Code Execution in Quarkus via Qute Template Engine

The Qute template engine in Quarkus fails to properly restrict access to sensitive Java internals, allowing an attacker to achieve remote code execution via template injection.

Quarkus vulnerability rce java
2t 1c
medium advisory

Denial of Service Vulnerabilities in RHEL pipewire and dbus-broker

Multiple vulnerabilities in the pipewire and dbus-broker components of Red Hat Enterprise Linux allow an attacker to trigger a Denial of Service condition through system instability or service disruption.

Enterprise Linux +1 privilege-escalation linux red-hat
2t 2c updated
low advisory

CVE-2026-81624: Resource Exhaustion in Undertow WebSocket Implementation

A vulnerability in the Undertow web server used in JBoss EAP and WildFly allows remote attackers to trigger denial of service through WebSocket resource exhaustion due to unconfigurable limits.

JBoss EAP +2 denial-of-service webserver java
1t 1c
medium advisory

Local Privilege Escalation in Red Hat Automatic Bug Reporting Tool

The Red Hat Automatic Bug Reporting Tool (ABRT) contains a local privilege escalation vulnerability (CVE-2015-5287) that allows unauthorized users to gain elevated access via symlink attacks.

Automatic Bug Reporting Tool
1t 1c
low advisory

CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability

Red Hat Libuser contains a race condition vulnerability allowing authenticated local users to corrupt /etc/passwd, potentially leading to privilege escalation or denial of service.

Libuser
1t 1c
high threat

BlueZ Stack-Based Buffer Overflow in Bluetooth Discovery

A stack-based buffer overflow in the BlueZ Linux Bluetooth stack allows an adjacent attacker to trigger a denial-of-service or potential code execution via a malformed Extended Inquiry Response packet.

exploited Red Hat Enterprise Linux 10 +4
1t 1c
high advisory

NetworkManager Local Privilege Escalation and Credential Theft via CA Path Manipulation

An improper authorization vulnerability in NetworkManager allows unprivileged local users to bypass 802.1X server certificate validation, facilitating credential theft through rogue access points.

NetworkManager +7 credential-access local-privilege-escalation linux networking 802.1x vulnerability
1t 2c
high advisory

Macro Injection Vulnerability in rpmbuild (CVE-2026-78367)

A macro injection vulnerability in rpmbuild allows remote attackers to achieve arbitrary code execution by convincing a user to process a specially crafted tarball.

Red Hat Enterprise Linux 7 +4 vulnerability rce rpmbuild rhel
1t 1c
high advisory

Integer Overflow in GNU Emacs PBM/PPM/PGM Image Loader (CVE-2026-77219)

GNU Emacs versions prior to 31.0.91 are susceptible to an integer overflow vulnerability in the PBM/PPM/PGM image loader, potentially leading to heap memory disclosure.

Emacs +1 vulnerability command-injection local-exploitation
1t 1c updated
low advisory

Authorization Flaw in Red Hat Multicluster Engine Clusterclaims-controller

A vulnerability in the Red Hat multicluster engine (MCE) allows authenticated tenants to delete unauthorized ManagedCluster resources due to a missing ownership check in the clusterclaims-controller.

multicluster engine
1t 1c
high advisory

Information Disclosure in Red Hat Advanced Cluster Management via HelmRelease Manipulation

An authenticated user with HelmRelease creation permissions can exploit CVE-2026-73137 to exfiltrate sensitive credentials from arbitrary Kubernetes namespaces in Red Hat Advanced Cluster Management.

Advanced Cluster Management exfiltration vulnerability cloud kubernetes
1t 1c
critical advisory

Privilege Escalation in multicloud-operators-subscription

A privilege escalation vulnerability in the multicloud-operators-subscription component allows tenants to perform unauthorized resource deployment via the HelmRelease controller.

multicloud-operators-subscription
1t 1c
high advisory

Red Hat Advanced Cluster Management Lighthouse Component DNS Hijacking

A vulnerability in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes allows a compromised spoke cluster to perform Man-in-the-Middle attacks via malicious EndpointSlice advertisements.

Advanced Cluster Management for Kubernetes kubernetes vulnerability cloud-native cve
2t 1c
high advisory

Arbitrary Mount Vulnerability in Kata Containers Confidential Containers

A vulnerability in Kata Containers, specifically when using genpolicy for Confidential Containers guest protection, allows a malicious host operator to bypass mount and storage rule validations during CreateContainer operations.

Red Hat OpenShift Container Platform 4 +1 privilege-escalation container-security cloud-security
1t 1c
high advisory

Credential Guessing Vulnerability via WildFly Elytron Unicode Normalization

A vulnerability in WildFly Elytron's password normalization logic allows attackers to bypass intended password character entropy, facilitating unauthorized access through dictionary-based credential guessing.

Red Hat build of Apache Camel 4 for Quarkus 3 +5 credential-access vulnerability middleware
1t 1c
high advisory

Pipelines-as-Code GitHub App Credential Exfiltration via Header Injection

Pipelines-as-Code (CVE-2026-54167) is vulnerable to GitHub App JWT exfiltration because it incorrectly trusts the 'X-GitHub-Enterprise-Host' header to define the API endpoint before validating incoming webhook signatures.

Pipelines-as-Code cve-2026-54167 credential-theft red-hat webserver
2t
low advisory

Denial of Service Vulnerability in FreeIPA Migration Handler

An unauthenticated remote denial-of-service vulnerability in FreeIPA, tracked as CVE-2026-73197, allows attackers to exhaust system memory by sending oversized form POST requests to the migration endpoint.

FreeIPA +4 denial-of-service vulnerability cve-2026-73197
1r 1t 1c
high advisory

Integer Overflow Vulnerability in libvirt NodeGetFreePages RPC Handler

An integer overflow vulnerability (CVE-2026-18917) in the libvirt NodeGetFreePages RPC handler allows an unprivileged local user to trigger a heap buffer overflow and achieve potential local privilege escalation.

libvirt +5 vulnerability local-privilege-escalation linux
1t 1c
high advisory

Stack-Based Buffer Overflow in Binutils (CVE-2026-19582)

A stack-based buffer overflow vulnerability in binutils versions 2.46.1 and prior allows attackers to achieve arbitrary code execution by enticing a victim to process a maliciously crafted Portable Executable (PE) file.

binutils +3 vulnerability cve memory-corruption
1t 1c
high advisory

Supply Chain Vulnerability in acm-operator-bundle

CVE-2026-76139 allows attackers to perform remote code execution during the acm-operator-bundle build process by exploiting an unverified remote script download.

acm-operator-bundle
2t 1c
high advisory

Privilege Escalation in search-v2-operator via Arbitrary CR Manipulation

A vulnerability in the search-v2-operator allows a privileged user to manipulate Custom Resource fields, leading to secret exfiltration and container image replacement.

search-v2-operator privilege-escalation cloud-security kubernetes
1t 1c
low advisory

Memory Exhaustion Denial of Service in cockpit-ws (CVE-2026-76235)

A heap-based memory leak in the cockpit-ws service allows unauthenticated remote attackers to trigger a denial of service via malformed Cookie headers.

cockpit-ws
1t 1c
high advisory

Remote Code Execution Vulnerability in Red Hat OpenShift Container Platform

A critical remote code execution vulnerability, tracked as CVE-2024-8979, allows unauthenticated remote attackers to execute arbitrary code within the Red Hat OpenShift Container Platform environment.

OpenShift Container Platform vulnerability cloud-security rce
1c
high advisory

Account Takeover Vulnerability in Keycloak Legacy Account-Linking Endpoint

Keycloak suffers from a vulnerability in its legacy client-initiated account-linking endpoint where predictable hashes allow attackers to forge linking URLs, facilitating unauthorized account takeover.

Keycloak
1t 1c updated
critical advisory

Excessive RBAC Permissions in Submariner-Operator

A critical RBAC vulnerability in the submariner-operator component allows a compromised Kubernetes cluster to overwrite endpoint configurations, enabling inter-cluster traffic interception.

Red Hat Advanced Cluster Management for Kubernetes 2 kubernetes cloud privilege-escalation rbac rhacm cve
1t 1c updated
critical advisory

Critical Authentication Bypass in Red Hat Build of Keycloak

A critical vulnerability (CVE-2026-18963) in the keycloak-services component allows unauthenticated attackers to hijack user accounts by bypassing password reset verification requirements.

PoC Red Hat Build of Keycloak +1 authentication-bypass identity-management cve-2026-18963
1t 1c updated
high advisory

Credential Exfiltration via AAP Controller Vault Plugin

A vulnerability in the Red Hat Ansible Automation Platform controller allows authenticated attackers to exfiltrate Kubernetes service account tokens via the HashiCorp Vault credential plugin.

Ansible Automation Platform credential-access exfiltration vulnerability
1t 1c
high advisory

Privilege Escalation in managedcluster-import-controller

A privilege escalation vulnerability in the managedcluster-import-controller allows a compromised spoke cluster service account to escalate privileges on the hub cluster by submitting malformed Certificate Signing Requests.

managedcluster-import-controller
1t 1c
critical advisory

Privilege Escalation in Red Hat Multicluster Global Hub

A critical authorization vulnerability in the multicloud-operators-subscription component allows low-privileged users to escalate privileges and perform unauthorized resource deployment via crafted Subscription annotations.

Multicluster Global Hub
1t 1c
medium advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux glib2

Multiple vulnerabilities in the glib2 library for Red Hat Enterprise Linux, identified as CVE-2024-52532 and CVE-2024-52533, allow remote attackers to perform denial-of-service attacks or achieve information disclosure.

Enterprise Linux vulnerability linux rhel glib2 privilege-escalation
1t 2c updated
critical advisory

Red Hat Multicluster Engine Confused Deputy Vulnerability

An authenticated tenant can exploit CVE-2026-73266 in the Red Hat Multicluster Engine clusterclaims-controller to perform a cross-tenant cluster join, enabling the unauthorized injection of workloads and policies.

Multicluster Engine for Kubernetes cve-2026-73266 kubernetes privilege-escalation multitenancy cloud-native vulnerability cve-2026-66794 supply-chain
4t 1c updated
low advisory

Denial of Service Vulnerability in Red Hat WildFly and JBoss EAP

A vulnerability in Red Hat WildFly and JBoss Enterprise Application Platform allows a remote, unauthenticated attacker to trigger a denial-of-service condition.

WildFly +1
1t 1c
medium advisory

Denial of Service Vulnerability in gnome-remote-desktop

A vulnerability in the gnome-remote-desktop component of Red Hat Enterprise Linux enables a remote, unauthenticated attacker to cause a denial of service condition.

Red Hat Enterprise Linux
1t
critical advisory

Remote Code Execution via Search Custom Resource in Red Hat Advanced Cluster Management

An administrative user on the Red Hat Advanced Cluster Management hub can exploit a flaw in the Collector.ImageOverride field to deploy arbitrary container images and achieve remote code execution across managed clusters.

acm-search-v2-rhel9 vulnerability command-injection sql-injection kubernetes
1t 1c updated
critical advisory

CVE-2026-72526: Improper Validation in Multicloud-Integrations Component

An authenticated tenant with Application creation permissions can exploit an improper input validation flaw in the multicloud-integrations Application propagation controller to achieve remote code execution on managed clusters.

multicloud-integrations
3t 1c
high advisory

CVE-2026-73122: Unauthorized Information Disclosure in Red Hat Advanced Cluster Management

A vulnerability in the multicloud-operators-channel component of Red Hat Advanced Cluster Management allows compromised agents to perform unauthorized reads of Secrets and ConfigMaps within hub Channel namespaces, risking credential exposure.

Advanced Cluster Management vulnerability cloud-security rhacm cve-2026-73122
1t 1c
high advisory

Information Disclosure in multicloud-operators-subscription via Improper Cross-Namespace Secret Reference

A vulnerability in the multicloud-operators-subscription controller allows a namespace administrator to exfiltrate sensitive secret contents by manipulating cross-namespace resource references.

multicloud-operators-subscription
1t 1c
high advisory

Code Injection Vulnerability in Perl DBI

An incomplete patch for CVE-2026-14380 introduced a code injection vulnerability (CWE-94) in the perl-DBI package for Red Hat Enterprise Linux 9 and 10, potentially allowing authenticated attackers to execute arbitrary code.

Red Hat Enterprise Linux 9 +2 vulnerability rce rhel
1t 1c
low advisory

Security Bypass Vulnerability in Red Hat OpenShift oauth-proxy

A vulnerability in the Red Hat OpenShift oauth-proxy component, identified as CVE-2024-5254, allows a remote authenticated attacker to bypass security controls and manipulate data.

OpenShift Container Platform
1c
high advisory

Unauthenticated Remote Code Execution in Red Hat JBoss EAP via openjdk-orb

CVE-2026-15560 allows unauthenticated remote code execution in Red Hat JBoss EAP environments configured with the -secmgr flag due to insecure object unmarshalling.

JBoss Enterprise Application Platform remote-code-execution vulnerability jboss denial-of-service web-server enterprise-application java jndi
5t 4c updated
high threat

Remote Code Execution in JBoss Marshalling via Infinispan

A deserialization vulnerability in JBoss Marshalling allows remote attackers to achieve code execution through the Infinispan session replication path.

exploited JBoss Marshalling +1
2t 1c
high advisory

Undertow AJP Authentication Bypass via CVE-2026-15554

The Undertow AJP listener incorrectly trusts ssl_cert and is_ssl attributes within the AJP protocol without validating a shared secret, allowing unauthenticated attackers to bypass CLIENT-CERT authentication.

Undertow vulnerability authentication-bypass network-security
2t 1c
critical advisory

PicketLink Federation SAML Authentication Bypass via Forged Assertions

A vulnerability in the PicketLink Federation SAML unsolicited response handler allows unauthenticated attackers to forge assertions, resulting in full authentication bypass as any principal.

PicketLink Federation authentication-bypass saml picketlink vulnerability
1t 1c
high advisory

Improper Configuration in Red Hat OpenShift AI MaaS Gateway

A configuration vulnerability in the Red Hat OpenShift AI (RHOAI) MaaS Gateway enables low-privileged users to intercept and manipulate model-serving traffic, resulting in the unauthorized disclosure of access keys and AI prompts.

OpenShift AI vulnerability cloud-security information-disclosure
2t 1c
high advisory

Privilege Escalation in RHOAI training-operator via CVE-2026-18982

A privilege escalation vulnerability in the RHOAI training-operator allows authenticated users with standard Kubernetes edit or admin roles to achieve host filesystem access and remote code execution through the creation of malicious training jobs.

RHOAI training-operator privilege-escalation cloud-security kubernetes cve-2026-18982
2t 1c
high advisory

CVE-2026-18949: Privilege Escalation via Overly Permissive Service Account in Open Data Hub

A vulnerability in the Open Data Hub odh-dashboard allows an attacker with a compromised Service Account token to escalate to cluster-administrator privileges due to excessive RBAC permissions.

odh-dashboard privilege-escalation cloud-native kubernetes
2t 1c
high advisory

Excessive Permissions Vulnerability in Data Science Pipelines Operator

The Data Science Pipelines Operator (DSPO) ClusterRole contains excessive permissions that allow an attacker who compromises the operator pod to escalate privileges to cluster administrator.

Data Science Pipelines Operator privilege-escalation kubernetes cloud-security
2t 3c
high advisory

Arbitrary Code Execution in trustyai-service-operator via Sidecar Injection

An authenticated user within a Kubernetes cluster can exploit the LMEvalJob controller in trustyai-service-operator to bypass security policies via custom sidecar containers, enabling arbitrary code execution.

trustyai-service-operator
2t 1c
high advisory

Improper Validation Vulnerability in multicluster-global-hub

A vulnerability in the multicluster-global-hub manager component allows an attacker with a compromised managed hub's Kafka client certificate to impersonate other hubs and manipulate status data.

multicluster-global-hub
1t 1c
medium advisory

Local Arbitrary Code Execution Vulnerability in RHEL gpsd

A local arbitrary code execution vulnerability in the gpsd component of Red Hat Enterprise Linux allows a local attacker to execute arbitrary code.

Enterprise Linux +1 vulnerability rhel linux
1t
high advisory

CVE-2026-16443: Signature Validation Bypass in Keycloak SAML Metadata Import

An authentication bypass vulnerability in Red Hat Build of Keycloak allows unauthenticated attackers to forge SAML assertions by manipulating metadata import settings to disable signature validation.

Red Hat Build of Keycloak authentication-bypass saml identity-management
2t 1c
medium advisory

Arbitrary Code Execution in Red Hat Ansible Automation Platform

A vulnerability in Red Hat ansible-core allows local attackers to achieve arbitrary code execution through improper input handling.

Ansible Automation Platform +1 vulnerability rce automation
1t 1c
critical advisory

Privilege Escalation in Red Hat Advanced Cluster Management

An insecure configuration in the Red Hat Advanced Cluster Management Application Subscription controller allows users with namespace-scoped edit privileges to escalate to cluster-admin by deploying unauthorized cluster-scoped resources via Helm charts.

Advanced Cluster Management for Kubernetes +1 privilege-escalation kubernetes cve vulnerability cloud credential-access
2t 2c updated
high advisory

Local Code Execution Vulnerability in Red Hat Enterprise Linux AI

A local vulnerability in Red Hat Enterprise Linux AI enables attackers to execute arbitrary code, potentially resulting in full system compromise or denial-of-service.

Enterprise Linux AI
1t
high advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux Perl Modules

Multiple vulnerabilities in Red Hat Enterprise Linux within DBI and perl-GD components allow local or remote attackers to execute arbitrary code, manipulate data, or trigger denial-of-service conditions.

Enterprise Linux +1 linux vulnerability perl rhel
1t
critical threat

Denial of Service Vulnerability in Red Hat Multicluster Engine for Kubernetes

A vulnerability in Red Hat Multicluster Engine for Kubernetes allows an unauthenticated remote attacker to trigger a denial of service condition by exploiting a software flaw.

exploited multicluster engine for Kubernetes denial-of-service kubernetes cloud-native vulnerability privilege-escalation cloud-security cve
2t updated
high advisory

Multiple Vulnerabilities in Red Hat Ansible Automation Platform

Multiple vulnerabilities in Red Hat Ansible Automation Platform allow a remote, unauthenticated attacker to achieve remote code execution or manipulate information displayed by the platform.

Ansible Automation Platform vulnerability remote-code-execution enterprise-automation
2t
high advisory

CVE-2026-18141: mTLS Bypass in Ansible Automation Platform

An unauthenticated remote attacker can bypass mTLS authentication in the aap-gateway component of Event-Driven Ansible to inject arbitrary events and trigger automated workflows.

Ansible Automation Platform cve-2026-18141 authentication-bypass automation
1t 1c
medium threat

Denial of Service in gnome-remote-desktop via Connection Throttling Bypass

A vulnerability in gnome-remote-desktop allows an unauthenticated remote attacker to exhaust system resources by bypassing connection throttling when RDP is enabled in system mode on Red Hat Enterprise Linux.

exploited Red Hat Enterprise Linux denial-of-service linux rdp cve-2026-18358
1t 1c
high advisory

Red Hat Advanced Cluster Security Policy Bypass via Deployment Label Manipulation

A vulnerability in Red Hat Advanced Cluster Security for Kubernetes (RHACS) allows an authenticated user to bypass security policy enforcement by setting the 'openshift.io/encoded-deployment-config' label to 'null'.

Advanced Cluster Security for Kubernetes kubernetes cloud-security defense-evasion cve-2026-10079
1t 1c
medium advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux ABRT

Multiple vulnerabilities in the Automatic Bug Reporting Tool (abrt) within Red Hat Enterprise Linux allow a local attacker to perform privilege escalation, manipulate data, or trigger a denial-of-service condition.

Enterprise Linux +1
1t
medium advisory

Credential Exfiltration via koku-metrics-operator SSRF

An SSRF vulnerability in the koku-metrics-operator allows an authenticated user to exfiltrate the cluster-global Red Hat pull-secret token by specifying an arbitrary destination URL within the CostManagementMetricsConfig resource.

Cost Management Metrics Operator
1t
low advisory

Denial of Service Vulnerabilities in RHEL perl-Archive-Tar and httplib2

Multiple vulnerabilities in Red Hat Enterprise Linux packages perl-Archive-Tar and httplib2 can be exploited by a remote, anonymous attacker to cause a Denial of Service condition.

Enterprise Linux +2 vulnerability denial-of-service linux
1t 2c
high advisory

Privilege Escalation Vulnerability in Performance Co-Pilot linux_sockets Module

A file descriptor leak in the Performance Co-Pilot (PCP) linux_sockets module allows an attacker with initial code execution to escalate privileges to root.

Performance Co-Pilot +8 privilege-escalation linux cve-2026-16526 remote-code-execution cve-2026-16527 monitoring-tool denial-of-service vulnerability +1
1r 1t 1c
high advisory

Command Injection in PCP linux_sockets PMDA

A command injection vulnerability (CVE-2026-16524) in the PCP linux_sockets PMDA allows local attackers to execute arbitrary commands by injecting shell metacharacters into the network.persocket.filter metric.

pcp +5 vulnerability command-injection linux
1t 1c
critical advisory

Hard-coded Credentials in Care Everywhere Gateway WildFly Management Interface

An unauthenticated remote code execution vulnerability exists in Care Everywhere Gateway 14.3.10 due to hard-coded credentials within the bundled WildFly 8.2.0.Final management interface.

Care Everywhere Gateway +1
2t 1c
high advisory

Authorization Bypass in Red Hat Quay

An incorrect authorization vulnerability in Red Hat Quay allows read-only superusers to view and impersonate robot account tokens, potentially leading to unauthorized repository access.

Red Hat Quay 3 privilege-escalation container-security auth-bypass
1t 1c
high threat

Red Hat Enterprise Linux librest and pipewire Vulnerabilities Allow Code Execution

An attacker can exploit multiple vulnerabilities found in Red Hat Enterprise Linux, specifically within the librest and pipewire components, to bypass security measures and achieve arbitrary code execution on affected systems, posing a significant risk to the integrity and confidentiality of the system.

exploited Red Hat Enterprise Linux linux vulnerability redhat code-execution defense-evasion
2t
high advisory

CRIU Restartable Sequences Vulnerability Allows Container Privilege Escalation

A flaw, CVE-2026-18107, in CRIU's handling of restartable sequences (rseq) during checkpoint/restore allows a malicious process inside a container to hijack CRIU's parasite code injection, enabling the spoofing of process credentials in the checkpoint image and leading to elevated capabilities and zeroed UIDs/GIDs upon restore.

CRIU +3 container-security privilege-escalation linux cloud-native
1t 1c
high advisory

CVE-2026-16313: sg3_utils Vulnerability Allows Root Command Execution via Crafted SCSI Device

A vulnerability, CVE-2026-16313, exists in the `sg_inq` command of `sg3_utils` on Red Hat Enterprise Linux systems, allowing an attacker who can present a specially crafted SCSI device to inject arbitrary properties into the `udev` device database by embedding a newline character in the device's name string, leading to arbitrary command execution as root when the device is disconnected.

sg3_utils linux vulnerability privilege-escalation arbitrary-command-execution
2t 1c 3i
high advisory

CVE-2026-49332: OpenShift OAuth Proxy Header Smuggling Vulnerability

A flaw in Red Hat OpenShift's oauth-proxy, tracked as CVE-2026-49332, allows an authenticated low-privilege user to smuggle a forged identity header by exploiting differences in how dash and underscore variants of 'X-Forwarded-User' are handled, potentially leading to privilege escalation in upstream applications.

Red Hat OpenShift Container Platform 4 +1 cloud vulnerability privilege-escalation header-smuggling openshift red-hat cve
1t 1c
high advisory

CVE-2026-12383: Event-Driven Ansible Server Authentication Bypass

A flaw in the Event-Driven Ansible (EDA) server's ExternalEventStreamViewSet allows an unauthenticated attacker to bypass mTLS authentication by spoofing the Subject HTTP header, enabling injection of arbitrary events into mTLS-protected streams and triggering downstream automation actions, while also leaking the expected certificate Distinguished Name in 403 error responses.

Event-Driven Ansible vulnerability network ansible
1r 2t 1c
high advisory

CVE-2026-17527: Kubernetes CDI Privilege Escalation and Data Exfiltration

A vulnerability in the Containerized Data Importer (CDI) for Kubernetes, identified as CVE-2026-17527, allows privilege escalation and data exfiltration through an improperly configured `cdi.kubevirt.io:view` ClusterRole, enabling attackers with partial access to clone and access data from any PersistentVolumeClaim in the cluster.

Containerized Data Importer containerization kubernetes privilege-escalation data-exfiltration cloud
3t 1c
high advisory

Kernel Local Privilege Escalation Vulnerability CVE-2026-17523

A critical local privilege escalation (LPE) vulnerability, tracked as CVE-2026-17523 and identified as an Expired Pointer Dereference (CWE-825), exists within the kernel, primarily affecting Red Hat Enterprise Linux 8, enabling an unprivileged local user to execute arbitrary code within the kernel, leading to root privileges and full control over the compromised system.

Red Hat Enterprise Linux 8 privilege-escalation kernel-vulnerability linux lpe cve
1t 1c
high advisory

Red Hat Advanced Cluster Management Vulnerability Allows Cluster-Admin Privilege Escalation

A flaw exists in the cluster-proxy service-proxy component of Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE), allowing an authenticated hub principal to inject an Impersonate-Group header into proxied requests, bypassing validation, and leveraging the spoke ServiceAccount's unrestricted impersonation permissions to escalate privileges to cluster-admin on all managed clusters.

Red Hat Advanced Cluster Management for Kubernetes +1 privilege-escalation vulnerability kubernetes cloud red-hat
1t 1c
medium advisory

Red Hat Quay Vulnerability Allows Authenticated Remote Attacker to Bypass Security

An authenticated remote attacker can exploit a vulnerability in Red Hat Quay to bypass security measures, circumventing established security controls within the container registry.

Red Hat Quay red-hat quay vulnerability security-bypass container-registry
1t
low advisory

CVE-2026-64611: libcupsfilters Denial of Service via Malformed Printer Advertisement

A high-severity denial of service vulnerability, CVE-2026-64611, exists in the `cfIEEE1284NormalizeMakeModel()` function of libcupsfilters, allowing a network-adjacent attacker to cause sustained CPU consumption and system unresponsiveness by broadcasting a specially crafted printer advertisement with an empty model field in the IEEE-1284 device ID.

libcupsfilters +5 vulnerability denial-of-service linux printer-vulnerability
1t 1c
high advisory

CVE-2026-16745: Authentication Bypass in Red Hat OpenShift AI odh-dashboard

A critical vulnerability, CVE-2026-16745, exists in the odh-dashboard web console component of Red Hat OpenShift AI (RHOAI), allowing a malicious actor within the cluster to bypass authentication by providing an arbitrary access token, leading to user impersonation and unauthorized access to the Kubernetes API, potentially resulting in arbitrary code execution, privilege escalation, and information disclosure.

odh-dashboard +1 cloud-security kubernetes authentication-bypass privilege-escalation arbitrary-code-execution red-hat
4t 1c
high advisory

Ansible Lightspeed VS Code Extension Command Injection Vulnerability (CVE-2026-44190)

A command injection vulnerability (CVE-2026-44190, CWE-78) in the Ansible Lightspeed Visual Studio Code extension allows remote attackers to execute arbitrary commands on a user's system due to improper validation of the `ansible.python.activationScript` setting, leading to complete system control when a malicious project is opened.

Ansible Lightspeed Visual Studio Code extension +1 command-injection vscode-extension remote-code-execution vulnerability
1t 1c
medium advisory

Ansible: Local Code Execution Vulnerability

A local attacker can exploit a vulnerability within Ansible software to execute arbitrary code on the affected system, potentially leading to further compromise or unauthorized actions on the host where Ansible is running.

Ansible vulnerability code-execution red-hat
1t
high advisory

Multiple Vulnerabilities in Red Hat Ansible Automation Platform

Multiple vulnerabilities exist in Red Hat Ansible Automation Platform, stemming from issues in components such as node-tar, linkify-it, protobufjs, brace-expansion, fast-uri, and DOMPurify. A remote, unauthenticated attacker can exploit these flaws to bypass security measures, perform Cross-Site Scripting (XSS) attacks, manipulate data, trigger Denial-of-Service (DoS) conditions, or execute arbitrary code on the affected system.

Ansible Automation Platform remote-code-execution xss denial-of-service data-manipulation vulnerability ansible red-hat
5t
high threat

Red Hat Enterprise Linux Vulnerabilities Allow Privilege Escalation and DoS

Multiple vulnerabilities in Red Hat Enterprise Linux, affecting components such as sssd, glib, and c-ares, can be exploited by an attacker to gain administrator privileges, bypass security measures, manipulate data, and trigger a denial-of-service condition.

exploited Red Hat Enterprise Linux red-hat linux vulnerability privilege-escalation defense-evasion denial-of-service
4t
high advisory

Unusual Child Process Execution by Web Servers on Linux

This detection rule identifies suspicious child process executions originating from web server processes on Linux systems, indicating that attackers may have exploited web application vulnerabilities such as command injection or remote file inclusion to establish persistence or execute malicious commands.

Elastic Defend +45 persistence execution command-and-control initial-access linux webserver webshell privilege-escalation +4
2r 5t 13i updated
medium advisory

Suspicious Command Execution via Linux Web Server

This brief describes how attackers exploit vulnerabilities in web applications to execute suspicious shell commands via web server processes on Linux, enabling persistence, discovery, credential access, and reverse shell establishment, which can lead to full system compromise and data exfiltration.

Apache HTTP Server +45 webserver command-injection web-shell vulnerability-exploitation persistence linux
1r 14t
critical advisory

CVE-2026-16242: Konnectivity Proxy-Server Authentication Bypass

A critical authentication bypass vulnerability, CVE-2026-16242, exists in the Konnectivity proxy-server configuration for hosted control planes, allowing a remote unauthenticated attacker to connect as an agent and potentially proxy, inspect, modify, or drop control-plane-to-node traffic due to improper client certificate validation.

Logging Subsystem for Red Hat OpenShift +2 kubernetes cloud vulnerability authentication-bypass redhat
4t 1c
high advisory

PipeWire Vulnerability CVE-2026-5674 Allows Sandbox Escape and Arbitrary Code Execution

A critical vulnerability, CVE-2026-5674, exists in PipeWire, a multimedia server, enabling an attacker to escape sandboxed applications like Flatpak by exploiting its PulseAudio compatibility layer to load a malicious library, leading to arbitrary code execution outside the sandbox and potential system compromise.

PipeWire +2 sandbox-escape privilege-escalation arbitrary-code-execution linux flatpak
4t 1c
high threat

Red Hat OpenShift Container Platform Vulnerability Allows Security Bypass

A vulnerability in the Red Hat OpenShift Container Platform allows a local attacker to bypass security controls, potentially leading to unauthorized access or further compromise of the platform.

exploited OpenShift Container Platform vulnerability cloud container
1t
medium advisory

Red Hat Quay: Multiple Vulnerabilities

Multiple vulnerabilities in Red Hat Quay allow a remote, authenticated attacker to execute arbitrary code and perform Server-Side Request Forgery (SSRF) attacks.

Red Hat Quay vulnerability-exploitation rce ssrf network
3t
low advisory

Feast Feature Server Denial of Service via Unauthenticated WebSocket Connections (CVE-2026-23538)

A vulnerability (CVE-2026-23538) exists in the Feast Feature Server's /ws/chat endpoint, allowing remote attackers to establish numerous unauthenticated, persistent WebSocket connections. This exploit, a form of resource exhaustion (CWE-770), consumes server resources like memory, CPU, and file descriptors, leading to a complete denial of service for legitimate users. Affected versions are those prior to 0.59.0.

Feast Feature Server +1 denial-of-service vulnerability websocket resource-exhaustion feast-feature-server
1r 1t 1c
high advisory

Keycloak JWT Authorization Bypass via Disabled User Accounts (CVE-2026-1609)

A vulnerability exists in Keycloak when its JSON Web Token (JWT) authorization grant preview feature is enabled, allowing a remote attacker with low privileges to exploit CVE-2026-1609 by presenting a valid assertion token from an external identity provider to obtain a JWT for a user account that has been disabled, thereby bypassing access controls and gaining unauthorized access to sensitive resources.

Keycloak identity-management authorization-bypass jwt access-control
1t 1c
high advisory

CVE-2026-12382 - AAP Gateway Envoy Proxy Authentication Bypass

A critical authentication bypass vulnerability (CVE-2026-12382) exists in the AAP Gateway Envoy proxy configuration within Red Hat Ansible Automation Platform 2 where the non-mTLS route to EDA event streams fails to remove the Subject HTTP header from client requests, allowing an unauthenticated remote attacker to inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.

Red Hat Ansible Automation Platform 2 +1 cve authentication-bypass red-hat ansible proxy envoy
2t 1c
medium advisory

Red Hat Enterprise Linux (pacemaker) Vulnerability Enables Denial of Service

A vulnerability in Red Hat Enterprise Linux (pacemaker) allows a remote, unauthenticated attacker to perform a Denial of Service attack, potentially disrupting the availability of affected systems.

Red Hat Enterprise Linux denial-of-service vulnerability linux red-hat
1t
medium threat

OpenShift GitOps Operator Vulnerability Allows Denial of Service via ClusterRole Name Collision

A high-severity denial of service vulnerability, identified as CVE-2026-14251, exists in the OpenShift GitOps operator where a namespace-scoped Argo CD instance can trigger the deletion of a cluster-scoped Argo CD instance's ClusterRole by exploiting a name collision due to improper resource ownership validation.

exploited OpenShift GitOps operator +1 openshift kubernetes gitops denial-of-service vulnerability
1t 1c
high advisory

Red Hat Enterprise Linux Plexus-Utils Vulnerability Allows Remote Code Execution

A remote, unauthenticated attacker can exploit a vulnerability in Red Hat Enterprise Linux, specifically within the plexus-utils component, to execute arbitrary program code with user privileges, leading to system compromise.

Red Hat Enterprise Linux +2 linux vulnerability rce remote-code-execution
1t
high advisory

Unauthenticated Remote Code Execution in Argo CD Repo-Server (CVE-2026-15416)

An unauthenticated remote code execution vulnerability (CVE-2026-15416) exists in Argo CD's repo-server, the GitOps engine used by Red Hat OpenShift GitOps, allowing an attacker with network access to achieve RCE and deploy malicious Kubernetes resources, leading to potential cluster compromise.

Argo CD +3 kubernetes gitops rce cloud vulnerability cve
3t 1c
high advisory

CVE-2026-15584 Privilege Escalation in OpenShift incluster-checks Tool

A privilege escalation vulnerability, CVE-2026-15584, in Red Hat OpenShift's incluster-checks tool allows users with standard edit roles to obtain root access on cluster nodes by exploiting privileged debug pods with host filesystem access created in the shared default namespace.

OpenShift +1 privilege-escalation vulnerability red-hat kubernetes cloud-native
1t 1c
high threat

Multiple Vulnerabilities in Schneider Electric PowerChute Serial Shutdown

Multiple vulnerabilities, including CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, and CVE-2026-2401, in Schneider Electric PowerChute Serial Shutdown versions 1.4 and prior could allow attackers with adjacent network access and high privileges to overwrite critical system files via path traversal, forge or inject malicious log data, gain unauthorized account access through excessive authentication attempts, trigger denial-of-service conditions, or expose sensitive information.

exploited PowerChute Serial Shutdown ics ot vulnerability path-traversal crlf-injection dos log-tampering critical-infrastructure
5t 5c
high advisory

Shai-Hulud Campaign Activity

Tracking brief for the Shai-Hulud campaign; individual sightings are folded in as reported.

jscrambler 8.14.0 +102 campaign shai-hulud
20i updated
medium advisory

CVE-2026-59692: GStreamer DTLS Plugin Stack Buffer Overflow Leading to DoS

A stack buffer overflow vulnerability, CVE-2026-59692, exists in GStreamer's DTLS plugin, allowing a remote unauthenticated attacker to cause a denial of service by sending a crafted certificate with an oversized Subject Distinguished Name during a DTLS handshake, which the plugin prints into a fixed-size stack buffer without bounds checking, leading to a process crash.

DTLS plugin +2 denial-of-service buffer-overflow vulnerability dtls gstreamer linux high_confidence_source watchlist_match
2t 1c
high advisory

CVE-2026-59691: GStreamer rfbsrc Heap Buffer Overflow Leads to DoS

A heap buffer overflow vulnerability (CVE-2026-59691) exists in GStreamer's rfbsrc plugin, allowing a malicious RFB/VNC server to trigger an out-of-bounds heap write in connecting clients, leading to denial of service and potential memory corruption.

GStreamer rfbsrc plugin +2 vulnerability heap-overflow denial-of-service gstreamer linux red-hat cve
1t 1c
medium threat

Multiple Vulnerabilities in Red Hat Enterprise Linux Components libsolv and aardvark-dns

Multiple vulnerabilities in Red Hat Enterprise Linux components libsolv and aardvark-dns could allow an attacker to perform a Denial of Service attack, manipulate data, or disclose confidential information.

exploited Red Hat Enterprise Linux +2 vulnerability linux red-hat dos data-manipulation data-leak
3t
medium advisory

Red Hat Enterprise Linux: Golang Component Vulnerability Enables Denial of Service

A remote, unauthenticated attacker can exploit a vulnerability in Golang components within Red Hat OpenShift, Red Hat Ansible Automation Platform, and Red Hat Enterprise Linux to conduct a Denial of Service attack, leading to service disruption.

Red Hat OpenShift +2 vulnerability denial-of-service red-hat linux
1t
high threat

Red Hat Enterprise Linux (389-ds-base): Multiple Vulnerabilities Allow Code Execution and DoS

Multiple vulnerabilities in Red Hat Enterprise Linux and the 389-ds-base component allow a remote, authenticated attacker to execute arbitrary code or cause a Denial-of-Service condition.

exploited Red Hat Enterprise Linux +1 linux vulnerability code-execution denial-of-service red-hat
2t
medium advisory

Red Hat JBoss Enterprise Application Platform Cross-Site Scripting Vulnerability

A remote, unauthenticated attacker can exploit a Cross-Site Scripting (XSS) vulnerability in the 'io.undertow.jastow' component of Red Hat JBoss Enterprise Application Platform, allowing injection of malicious scripts into web pages which can lead to session hijacking, data theft, or defacement.

JBoss Enterprise Application Platform xss web-application jboss vulnerability red-hat
1t
high advisory

Red Hat Enterprise Linux (python-pip) Vulnerability Allows Remote Code Execution

A remote authenticated attacker can exploit a vulnerability in Red Hat Enterprise Linux, specifically within its python-pip component, to overwrite arbitrary files and potentially achieve arbitrary code execution, allowing for system compromise through authenticated remote access.

Red Hat Enterprise Linux +1 vulnerability-exploitation linux code-execution
2t
high threat

Red Hat Enterprise Linux (perl-HTTP-Daemon): Remote Code Execution Vulnerability

A remote, unauthenticated attacker can exploit a vulnerability in the 'perl-HTTP-Daemon' component within Red Hat Enterprise Linux to execute arbitrary program code with the privileges of the affected service, potentially gaining control over the compromised system.

exploited Red Hat Enterprise Linux +1 redhat linux vulnerability rce perl webserver
2t
high advisory

CVE-2026-14476: SSSD AD GPO Provider Path Traversal to Root File Write and Authentication Bypass

A path traversal vulnerability (CVE-2026-14476) in SSSD's Active Directory Group Policy Object (AD GPO) provider allows an authenticated attacker with AD GPO management access to write arbitrary files outside the GPO cache directory with root privileges, leading to Kerberos configuration injection and potential authentication bypass on Red Hat Enterprise Linux systems.

SSSD AD GPO provider +5 path-traversal privilege-escalation authentication-bypass kerberos linux red-hat sssd cve
5t 1c
critical advisory

CVE-2026-11610: 389 Directory Server SASL Heap Buffer Overflow Leading to DoS

A heap buffer overflow vulnerability (CVE-2026-11610) exists in the SASL I/O layer of 389 Directory Server (389-ds-base), active since version 1.3.2. An authenticated attacker can send a specially crafted, oversized LDAP UNBIND packet after a successful SASL bind with integrity protection. This causes approximately 2 megabytes of attacker-controlled data to overflow a 512-byte heap buffer in sasl_io_recv(), leading to a denial of service (server crash).

389 Directory Server +2 heap-overflow denial-of-service ldap sasl linux cve
1t 1c
high advisory

CVE-2026-58384: GIMP PSD Parser Integer Overflow Leads to RCE/DoS

An integer overflow vulnerability (CVE-2026-58384) exists in GIMP's PSD parser within the `read_RLE_channel()` function, leading to undersized heap allocations that can cause subsequent heap memory corruption, potentially resulting in denial of service or arbitrary code execution.

GIMP +1 vulnerability rce dos linux heap-overflow
2t 1c
high threat

CVE-2026-58380: GIMP PNM Parser Off-by-One Error Leads to RCE

A high-severity off-by-one error, CVE-2026-58380, in GIMP's PNM file format parser (specifically the `pnmscanner_gettoken()` function) allows an attacker to corrupt memory by crafting a malicious PNM file, potentially leading to denial of service or arbitrary code execution when the file is opened.

exploited GIMP +4 vulnerability memory-corruption buffer-overflow linux
1c
low advisory

Potential Proxy Execution via Systemd-run on Linux

This brief details how attackers may leverage the `systemd-run` utility on Linux systems for defense evasion and execution by running commands as detached, transient services or scopes to obscure their activities and parent-child process chains.

Acronis Cyber Protect +46 defense-evasion execution linux
1r 3t
medium advisory

CVE-2026-9165 - Red Hat Advanced Cluster Security for Kubernetes Central Component Denial of Service

An authenticated denial of service vulnerability (CVE-2026-9165) exists in the Red Hat Advanced Cluster Security for Kubernetes (RHACS) Central component, allowing attackers with a valid API token to send deeply nested GraphQL queries that cause excessive resource consumption and render the management plane unavailable.

Red Hat Advanced Cluster Security for Kubernetes +1 kubernetes red-hat dos vulnerability graphql
1t 1c
high advisory

Red Hat JBoss Enterprise Application Platform: Multiple Vulnerabilities

Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform allow a remote, unauthenticated attacker to execute arbitrary code, perform cross-site scripting (XSS) attacks, disclose sensitive information, cause a denial of service, or bypass security mechanisms, posing a significant risk of system compromise and data exposure.

JBoss Enterprise Application Platform vulnerability rce xss dos information-disclosure red-hat jboss enterprise-application-platform +1
5t
high advisory

CVE-2026-58379: GIMP Heap Buffer Overflow in PSP Parser Allows RCE

A heap buffer overflow vulnerability (CVE-2026-58379) in GIMP's Paint Shop Pro (PSP) file format parser allows a remote attacker to achieve arbitrary code execution or cause a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file, exploiting incorrect buffer size calculations when processing low bit-depth images.

GIMP +1 heap-buffer-overflow vulnerability image-processing
3t 1c
high advisory

Google Security Updates — July 2026

Roundup of Google security advisories published in July 2026.

golang.org/x/crypto/ssh +74 roundup
5c 41i updated
medium advisory

Red Hat Cloud Services npm Packages Hijacked

Multiple npm packages within the legitimate @redhat-cloud-services namespace have been hijacked with malicious code, posing a supply chain risk.

@redhat-cloud-services namespace npm supply-chain package-hijacking
2r
high advisory

Red Hat npm Packages Compromised by Miasma Malware

A supply chain attack compromised over 30 npm packages under Red Hat's '@redhat-cloud-services' namespace, distributing a credential-stealing malware variant named 'Miasma' that targets sensitive developer information.

@redhat-cloud-services npm packages +1 supply-chain credential-theft miasma npm
2r 2t
medium threat

Suspicious Command Execution via Web Server on Linux

Identifies suspicious command executions via a web server on Linux systems, which may suggest a vulnerability and remote shell access.

Elastic Defend +43 persistence initial-access vulnerability linux
2r 3t
high advisory

Red Hat Enterprise Linux (crun) Privilege Escalation Vulnerability

A local attacker can exploit a vulnerability in Red Hat Enterprise Linux (crun) to escalate their privileges, potentially gaining root access.

crun privilege-escalation linux
2r 1t
high advisory

CIFSwitch Linux Kernel Local Privilege Escalation Vulnerability

The CIFSwitch vulnerability in the Linux kernel allows an unprivileged user to forge CIFS authentication key descriptions, abuse the kernel's key request mechanism, and gain root privileges by loading a malicious NSS module.

Linux Mint +12 privilege-escalation linux cifs kernel
2r 1t
high advisory

OpenShift Router Vulnerability CVE-2026-46579: Mutual TLS Bypass via Header Injection

CVE-2026-46579 describes a vulnerability in the Red Hat OpenShift Router. When a Route is configured with `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend fails to remove `X-SSL-Client-*` headers from incoming requests, allowing unauthenticated attackers to bypass mutual TLS authentication and impersonate client certificate identities.

OpenShift Router openshift mtls header-injection cve-2026-46579
1r 2t 1c
medium advisory

OpenShift Router SSRF via FQDN EndpointSlice (CVE-2026-42965)

CVE-2026-42965 describes a server-side request forgery (SSRF) vulnerability in the OpenShift Router where a user with EndpointSlice write access can expose instance credentials by creating a service that proxies requests to a cloud metadata endpoint.

OpenShift Router ssrf cve openshift
1r 1t 1c
critical advisory

Red Hat Enterprise Linux Flatpak Multiple Vulnerabilities Allow Code Execution and File Deletion

An authenticated attacker can exploit multiple vulnerabilities in the Flatpak package of Red Hat Enterprise Linux to execute arbitrary program code and delete files.

Flatpak rhel vulnerability code_execution file_deletion
2r 1t
medium advisory

Red Hat OpenShift Tempo Vulnerabilities Allow Remote Exploitation

Multiple vulnerabilities in Red Hat OpenShift Tempo allow an unauthenticated remote attacker to bypass security measures, disclose sensitive information, manipulate data, or cause a denial of service condition.

OpenShift Tempo openshift tempo vulnerability
1r 3t
high advisory

CVE-2026-44604: RPM rpmuncompress Command Injection Vulnerability

A command injection vulnerability (CVE-2026-44604) exists in the `rpmuncompress` utility of RPM; when extracting specially crafted ZIP, 7z, or GEM archives, an attacker can inject shell commands via a malicious top-level folder name, leading to arbitrary code execution as the user running the extraction.

RPM command-injection CVE-2026-44604 archive-extraction linux
2r 1t 1c
medium advisory

Samba NTFS Reparse Point Vulnerability (CVE-2026-1933)

CVE-2026-1933 describes a vulnerability in Samba's handling of NTFS-style reparse points on read-only shares, allowing authenticated users with filesystem write permissions to modify reparse point metadata and potentially alter SMB-visible file behavior.

Samba cve cve-2026-1933 reparse point privilege escalation smb
2r 1t 1c
high threat

CVE-2026-42013: gnutls Certificate Validation Bypass via Oversized SAN

A vulnerability in gnutls (CVE-2026-42013) allows a remote attacker to bypass certificate validation by providing an oversized Subject Alternative Name (SAN), causing the validation process to fall back to the Common Name (CN) field, potentially leading to spoofing or man-in-the-middle attacks.

gnutls certificate validation spoofing man-in-the-middle CVE-2026-42013
2r 1t 1c
critical advisory

KubeVirt virt-handler Symlink Vulnerability Leading to Container Escape (CVE-2026-7374)

CVE-2026-7374 allows an authenticated OpenShift user with edit permissions in a single namespace to escalate privileges to full cluster control by exploiting improper symlink validation in KubeVirt's virt-handler component when connecting to VM console sockets.

virt-handler +1 kubeVirt openshift symlink container escape privilege escalation
2r 1t 1c
medium advisory

CVE-2026-9064: 389-ds-base Unauthenticated Remote Denial-of-Service

CVE-2026-9064 describes a denial-of-service vulnerability in 389-ds-base where an unauthenticated attacker can send a crafted LDAP request with excessive controls, causing excessive CPU consumption and heap allocation, leading to latency degradation, worker thread starvation, or out-of-memory termination.

389-ds-base denial-of-service ldap CVE-2026-9064
2r 1t 1c
medium threat

Keycloak OIDC Implicit Flow Bypass Vulnerability (CVE-2026-7571)

CVE-2026-7571 describes a vulnerability in Keycloak where a low-privilege user can bypass security controls intended to disable the implicit flow in OpenID Connect (OIDC) clients by manipulating client data during session restart, potentially exposing access tokens.

Keycloak oidc implicit-flow cve-2026-7571 credential-access
2r 1t 1c
high advisory

CVE-2026-7507: Keycloak Session Fixation Vulnerability in Login Actions Endpoints

A session fixation vulnerability in Keycloak's /login-actions/restart endpoint allows an unauthenticated attacker to hijack a user's session by crafting a malicious link that resets the authentication flow, potentially leading to account takeover.

Keycloak session fixation account takeover cve-2026-7507
2r 1t 1c
high advisory

Keycloak Open Redirect Vulnerability (CVE-2026-7504)

A vulnerability in Keycloak's URL validation allows attackers to redirect users to unauthorized URLs by exploiting discrepancies in the handling of the user-info component within URLs, potentially leading to sensitive information exposure.

Keycloak open-redirect cve cloud
2r 1t 1c
medium advisory

Podman Vulnerability Allows File Manipulation

A remote, authenticated attacker can exploit a vulnerability in Podman to manipulate files on the host system.

Podman file-manipulation linux
1r 1t
medium threat

Red Hat Enterprise Linux Valkey Vulnerabilities Lead to File Manipulation and Denial of Service

An authenticated or anonymous attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux regarding Valkey to manipulate files or cause a denial-of-service condition.

Red Hat Enterprise Linux valkey denial-of-service file-manipulation linux
2r 1t
medium advisory

Keycloak Security Bypass Vulnerability

An authenticated remote attacker can exploit a vulnerability in Keycloak to bypass security measures.

Keycloak security-bypass authentication
2r 1t
medium advisory

Multiple Vulnerabilities in Red Hat Build of Quarkus

An authenticated or unauthenticated remote attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux and Quarkus to perform a denial of service attack, disclose sensitive information, or manipulate data.

Quarkus +1 vulnerability redhat denial of service information disclosure data manipulation
2r 2t
high advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux and OpenShift Grafana Component

A remote anonymous attacker can exploit multiple vulnerabilities in the Grafana component of Red Hat Enterprise Linux and OpenShift to execute arbitrary code, disclose confidential information, and cause a denial-of-service condition.

Red Hat Enterprise Linux +1 grafana rhel openshift vulnerability code execution information disclosure denial of service
2r 3t
high advisory

Red Hat Enterprise Linux Cloud-Init Privilege Escalation Vulnerability

A vulnerability in the cloud-init component of Red Hat Enterprise Linux allows an attacker from an adjacent network to gain administrator privileges.

cloud-init privilege-escalation linux
1r 1t
medium advisory

Leveraging Linux Cgroups for Threat Detection and Investigation

This brief outlines how Linux cgroups, a kernel feature for resource management, can be repurposed to provide valuable telemetry for detecting malicious processes, particularly in systemd, Docker, and Kubernetes environments, aiding in investigations of server compromises.

Red Hat Enterprise Linux +5 linux cgroups container kubernetes docker systemd threat-detection
2r
high advisory

Multiple Vulnerabilities in Kiali for Red Hat OpenShift Service Mesh

An anonymous remote attacker can exploit multiple vulnerabilities in Kiali for Red Hat OpenShift Service Mesh to gain extended privileges, bypass security measures, manipulate or disclose data, or cause a denial-of-service condition.

OpenShift Service Mesh +1 kiali openshift servicemesh vulnerability privilege-escalation defense-evasion impact discovery +1
2r 4t
critical advisory

Red Hat Enterprise Linux Multiple Vulnerabilities Leading to RCE/DoS

A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux to execute arbitrary code or cause a denial-of-service condition.

Enterprise Linux vulnerability rhel remote-code-execution denial-of-service linux
2r 2t
critical advisory

Multiple Vulnerabilities in Red Hat Build of Keycloak

Multiple vulnerabilities in Red Hat Build of Keycloak could allow an attacker to bypass authentication, gain elevated privileges, disclose sensitive information, cause a denial of service condition, execute arbitrary code, or manipulate data.

Build of Keycloak keycloak vulnerability authentication-bypass
2r 5t
high advisory

Red Hat Enterprise Linux (openEXR) Vulnerability Allows Code Execution

A remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux (openEXR) to execute arbitrary program code.

Red Hat Enterprise Linux code-execution rhel openEXR linux
2r 1t
medium advisory

Multiple Vulnerabilities in Red Hat Hardened Images RPMs

A remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Hardened Images RPMs to cause a denial-of-service condition and possibly manipulate data or perform path traversal attacks.

Hardened Images RPMs vulnerability denial-of-service path-traversal
2r 1t
high advisory

Podman HyperV Machine Vulnerability Allows Arbitrary Code Execution with Administrator Privileges

A local attacker can exploit a vulnerability in Podman HyperV Machine to execute arbitrary program code with administrator privileges, leading to complete system compromise.

Podman HyperV Machine privilege-escalation container windows
2r 1t
high threat

Dirty Frag Linux Kernel Local Privilege Escalation Vulnerability

The Dirty Frag vulnerability (CVE-2026-43284 and CVE-2026-43500) is a Linux kernel local privilege escalation that allows an unprivileged local user to gain root privileges by exploiting flaws in the networking subsystem to overwrite protected file contents in the page cache.

exploited Linux kernel linux privilege-escalation vulnerability dirty_frag
2r 1t
critical advisory

Red Hat Build of Debezium for Red Hat Application Foundations Vulnerabilities Allow Code Execution

Multiple vulnerabilities in Red Hat Build of Debezium for Red Hat Application Foundations could allow an attacker to execute arbitrary code.

Build of Debezium for Red Hat Application Foundations vulnerability code-execution debezium
2r 1t
high advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux

An unauthenticated or authenticated remote attacker can exploit vulnerabilities in Red Hat Enterprise Linux to perform cross-site scripting, cause denial of service, or disclose sensitive information.

Red Hat Enterprise Linux vulnerability xss dos redhat
2r 3t
medium advisory

Red Hat OpenShift Service Mesh Multiple Vulnerabilities

An anonymous remote attacker can exploit multiple vulnerabilities in Red Hat OpenShift Service Mesh to manipulate files, disclose information, or cause a denial-of-service condition.

OpenShift Service Mesh openshift servicemesh vulnerability dos
2r 4t
medium advisory

Dell Security Advisories Address Multiple Vulnerabilities

Dell published security advisories addressing vulnerabilities in APEX Cloud Platform, Automation Platform, Command | Monitor, CyberSense, NativeEdge Orchestrator, SmartFabric Manager, iDRAC, Disk Library, and PowerProtect Cyber Recovery, requiring users to apply necessary updates.

APEX Cloud Platform for Red Hat OpenShift +9 vulnerability patch dell
2r
critical advisory

Red Hat Advanced Cluster Management and Multicluster Engine Vulnerability Allows Remote Code Execution or DoS

A remote, authenticated attacker can exploit a vulnerability in Red Hat Advanced Cluster Management and Multicluster engine for Kubernetes to execute arbitrary program code or cause a denial of service condition.

Advanced Cluster Management +1 kubernetes rce dos redhat
2r 2t
high advisory

Red Hat Hardened Images RPMs Fontconfig Vulnerability

A local attacker can exploit a vulnerability in Red Hat Hardened Images RPMs to execute arbitrary code or cause a denial of service.

Hardened Images RPMs vulnerability code-execution denial-of-service linux
2r 2t
high advisory

Multiple Vulnerabilities in Red Hat Hardened Images RPMs

Multiple vulnerabilities in Red Hat Hardened Images RPMs can be exploited by an attacker to bypass security measures, escalate privileges, disclose sensitive information, manipulate data, or cause a denial-of-service condition.

Hardened Images RPMs vulnerability redhat rpm privilege-escalation defense-evasion information-disclosure manipulation denial-of-service
2r 5t
critical advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux and Satellite

Multiple vulnerabilities in Red Hat Enterprise Linux and Red Hat Satellite could allow a remote, anonymous attacker to disclose information or execute arbitrary code.

Red Hat Enterprise Linux +1 redhat rhel satellite vulnerability code-execution
2r 2t
medium advisory

Red Hat OpenShift Container Platform Security Bypass Vulnerability

A remote, authenticated attacker can exploit a vulnerability in Red Hat OpenShift Container Platform to bypass security measures.

OpenShift Container Platform openshift security-bypass defense-evasion
2r 1t
high advisory

Podman Desktop Vulnerability Allows Denial of Service and Information Disclosure

A remote, anonymous attacker can exploit a vulnerability in Podman Desktop to perform a denial of service attack and disclose sensitive information.

Podman Desktop denial-of-service information-disclosure podman
3r 2t
critical threat

Red Hat Enterprise Linux freeipmi Vulnerability Allows Code Execution

A remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux freeipmi to cause a denial of service condition or memory corruption, potentially allowing arbitrary code execution.

Enterprise Linux rhel freeipmi vulnerability code-execution dos
2r 4t
critical threat

Red Hat Enterprise Linux Vulnerability Allows Privilege Escalation and Code Execution

A remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux (python-wheel) to escalate privileges or execute arbitrary code.

Enterprise Linux privilege-escalation execution linux
2r 2t
high advisory

Quarkus Vertx HTTP Authorization Bypass via Matrix Parameters

Quarkus Vertx HTTP versions < 3.20.6.1, >= 3.21.0 and < 3.27.3.1, >= 3.30.0 and < 3.33.1.1, and >= 3.34.0 and < 3.35.1.1 are vulnerable to an authorization bypass where appending a semicolon and arbitrary text to the request URL allows unauthorized access to protected resources.

Quarkus Vertx HTTP +3 authentication-bypass authorization-bypass web-application
2r 2t
high advisory

AAP Gateway Account Hijacking Vulnerability (CVE-2026-6266)

CVE-2026-6266 allows a remote attacker to hijack user accounts in AAP gateway by manipulating the IDP-provided email during the user auto-linking process, potentially gaining unauthorized access, including administrative privileges.

AAP cve-2026-6266 account-hijacking authentication-bypass
2r 1t 1c
critical advisory

CVE-2026-31431 'Copy Fail' Linux Kernel Privilege Escalation

The 'Copy Fail' vulnerability (CVE-2026-31431) in the Linux kernel allows a local attacker to escalate privileges to root, potentially leading to container breakout and lateral movement in cloud environments.

Amazon Linux 2023 +3 privilege-escalation linux kernel
2r 1t 1c
high advisory

GnuTLS DTLS Handshake Parsing Flaw (CVE-2026-33845)

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read, potentially causing information disclosure or denial of service.

GnuTLS cve denial-of-service information-disclosure
2r 3t 1c
critical threat

Local Privilege Escalation Vulnerability 'Copy Fail' in Linux Kernel

A local privilege escalation vulnerability, dubbed 'Copy Fail' (CVE-2026-31431), affects Linux kernels released since 2017, allowing an unprivileged local attacker to gain root permissions by exploiting a logic bug in the authencesn cryptographic template.

Linux kernel +4 Theori privilege-escalation linux vulnerability
2r 1t 1c
high advisory

Multiple Vulnerabilities in Red Hat Enterprise Linux Fast Datapath

A remote, anonymous attacker can exploit multiple vulnerabilities in Fast Datapath for Red Hat Enterprise Linux to perform a denial-of-service attack or disclose sensitive information.

Fast Datapath redhat vulnerability denial-of-service
2r 4t
critical advisory

Multiple Vulnerabilities in Red Hat Linux Kernel

Multiple vulnerabilities in the Red Hat Linux kernel allow for arbitrary code execution, privilege escalation, and remote denial of service.

Red Hat CodeReady Linux Builder +1 vulnerability kernel redhat execution privilege-escalation denial-of-service
2r 3t 5c
high advisory

Red Hat Enterprise Linux LibRaw Multiple Vulnerabilities Allow Code Execution or DoS

Multiple vulnerabilities in Red Hat Enterprise Linux's LibRaw component allow a remote attacker to execute arbitrary code or cause a denial-of-service condition.

Enterprise Linux vulnerability code-execution denial-of-service linux
2r 2t
critical advisory

InstructLab Arbitrary Code Execution via Malicious HuggingFace Model

InstructLab is vulnerable to arbitrary code execution because the `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace, allowing remote attackers to execute code by convincing a user to load a malicious model.

InstructLab cve code-execution huggingface
2r 1t 1c
high advisory

Red Hat Enterprise Linux File Manipulation Vulnerability

An authenticated remote attacker can exploit a vulnerability in Red Hat Enterprise Linux (CPython) to manipulate files.

Red Hat Enterprise Linux rhel file-manipulation linux
2r 2t
high advisory

Red Hat Enterprise Linux Quarkus Vulnerabilities Lead to Information Disclosure and Denial of Service

Multiple vulnerabilities in Quarkus on Red Hat Enterprise Linux allow a remote attacker to disclose information or trigger a denial of service.

Red Hat Enterprise Linux +1 rhel quarkus denial-of-service information-disclosure linux
2r 2t
high advisory

Red Hat Integration Camel for Spring Boot Multiple Vulnerabilities

An anonymous remote attacker can exploit multiple vulnerabilities in Red Hat Integration Camel for Spring Boot to compromise confidentiality, availability, and integrity.

Red Hat Integration Camel for Spring Boot redhat camel springboot vulnerability webserver
2r 1t
high advisory

Unexpected Linux Auditd Daemon Shutdown

This analytic detects unexpected shutdowns of the Linux auditd daemon, potentially indicating attempts to disable security monitoring and evade detection by attackers.

Splunk Enterprise +3 auditd linux defense-evasion endpoint
3r 1t
medium advisory

Linux Auditd Daemon Abort Detection

Detection of abnormal Linux audit daemon (auditd) termination via DAEMON_ABORT events, indicating potential auditing subsystem failure due to resource exhaustion, corruption, or malicious interference.

Splunk Enterprise +3 auditd linux anomaly endpoint
2r 1t
medium advisory

Linux Auditd Daemon (Re)Initialization Detection

Detection of Linux audit daemon (auditd) re-initialization events, which can indicate attempts to re-enable audit logging after evasion or restarts with modified rule sets.

Splunk Enterprise +4 linux auditd anomaly
3r 1t