Vendor
Local Code Execution Vulnerability in Red Hat Enterprise Linux AI
1 TTPA local vulnerability in Red Hat Enterprise Linux AI enables attackers to execute arbitrary code, potentially resulting in full system compromise or denial-of-service.
Multiple Vulnerabilities in Red Hat Enterprise Linux Perl Modules
1 TTPMultiple vulnerabilities in Red Hat Enterprise Linux within DBI and perl-GD components allow local or remote attackers to execute arbitrary code, manipulate data, or trigger denial-of-service conditions.
Denial of Service Vulnerability in Red Hat Multicluster Engine for Kubernetes
1 TTPA vulnerability in Red Hat Multicluster Engine for Kubernetes allows an unauthenticated remote attacker to trigger a denial of service condition by exploiting a software flaw.
Multiple Vulnerabilities in Red Hat Ansible Automation Platform
2 TTPsMultiple vulnerabilities in Red Hat Ansible Automation Platform allow a remote, unauthenticated attacker to achieve remote code execution or manipulate information displayed by the platform.
CVE-2026-18141: mTLS Bypass in Ansible Automation Platform
1 TTP 1 CVEAn unauthenticated remote attacker can bypass mTLS authentication in the aap-gateway component of Event-Driven Ansible to inject arbitrary events and trigger automated workflows.
Denial of Service in gnome-remote-desktop via Connection Throttling Bypass
1 TTP 1 CVEA vulnerability in gnome-remote-desktop allows an unauthenticated remote attacker to exhaust system resources by bypassing connection throttling when RDP is enabled in system mode on Red Hat Enterprise Linux.
Red Hat Advanced Cluster Security Policy Bypass via Deployment Label Manipulation
1 TTP 1 CVEA vulnerability in Red Hat Advanced Cluster Security for Kubernetes (RHACS) allows an authenticated user to bypass security policy enforcement by setting the 'openshift.io/encoded-deployment-config' label to 'null'.
Multiple Vulnerabilities in Red Hat Enterprise Linux ABRT
1 TTPMultiple vulnerabilities in the Automatic Bug Reporting Tool (abrt) within Red Hat Enterprise Linux allow a local attacker to perform privilege escalation, manipulate data, or trigger a denial-of-service condition.
Credential Exfiltration via koku-metrics-operator SSRF
1 TTPAn SSRF vulnerability in the koku-metrics-operator allows an authenticated user to exfiltrate the cluster-global Red Hat pull-secret token by specifying an arbitrary destination URL within the CostManagementMetricsConfig resource.
Denial of Service Vulnerabilities in RHEL perl-Archive-Tar and httplib2
1 TTP 2 CVEsMultiple vulnerabilities in Red Hat Enterprise Linux packages perl-Archive-Tar and httplib2 can be exploited by a remote, anonymous attacker to cause a Denial of Service condition.
Privilege Escalation Vulnerability in Performance Co-Pilot linux_sockets Module
1 rule 1 TTP 1 CVEA file descriptor leak in the Performance Co-Pilot (PCP) linux_sockets module allows an attacker with initial code execution to escalate privileges to root.
Command Injection in PCP linux_sockets PMDA
1 TTP 1 CVEA command injection vulnerability (CVE-2026-16524) in the PCP linux_sockets PMDA allows local attackers to execute arbitrary commands by injecting shell metacharacters into the network.persocket.filter metric.
Hard-coded Credentials in Care Everywhere Gateway WildFly Management Interface
2 TTPs 1 CVEAn unauthenticated remote code execution vulnerability exists in Care Everywhere Gateway 14.3.10 due to hard-coded credentials within the bundled WildFly 8.2.0.Final management interface.
Authorization Bypass in Red Hat Quay
1 TTP 1 CVEAn incorrect authorization vulnerability in Red Hat Quay allows read-only superusers to view and impersonate robot account tokens, potentially leading to unauthorized repository access.
Red Hat Enterprise Linux librest and pipewire Vulnerabilities Allow Code Execution
2 TTPsAn attacker can exploit multiple vulnerabilities found in Red Hat Enterprise Linux, specifically within the librest and pipewire components, to bypass security measures and achieve arbitrary code execution on affected systems, posing a significant risk to the integrity and confidentiality of the system.
CRIU Restartable Sequences Vulnerability Allows Container Privilege Escalation
1 TTP 1 CVEA flaw, CVE-2026-18107, in CRIU's handling of restartable sequences (rseq) during checkpoint/restore allows a malicious process inside a container to hijack CRIU's parasite code injection, enabling the spoofing of process credentials in the checkpoint image and leading to elevated capabilities and zeroed UIDs/GIDs upon restore.
CVE-2026-16313: sg3_utils Vulnerability Allows Root Command Execution via Crafted SCSI Device
2 TTPs 1 CVE 3 IOCsA vulnerability, CVE-2026-16313, exists in the `sg_inq` command of `sg3_utils` on Red Hat Enterprise Linux systems, allowing an attacker who can present a specially crafted SCSI device to inject arbitrary properties into the `udev` device database by embedding a newline character in the device's name string, leading to arbitrary command execution as root when the device is disconnected.
CVE-2026-49332: OpenShift OAuth Proxy Header Smuggling Vulnerability
1 TTP 1 CVEA flaw in Red Hat OpenShift's oauth-proxy, tracked as CVE-2026-49332, allows an authenticated low-privilege user to smuggle a forged identity header by exploiting differences in how dash and underscore variants of 'X-Forwarded-User' are handled, potentially leading to privilege escalation in upstream applications.
CVE-2026-12383: Event-Driven Ansible Server Authentication Bypass
1 rule 2 TTPs 1 CVEA flaw in the Event-Driven Ansible (EDA) server's ExternalEventStreamViewSet allows an unauthenticated attacker to bypass mTLS authentication by spoofing the Subject HTTP header, enabling injection of arbitrary events into mTLS-protected streams and triggering downstream automation actions, while also leaking the expected certificate Distinguished Name in 403 error responses.
CVE-2026-17527: Kubernetes CDI Privilege Escalation and Data Exfiltration
3 TTPs 1 CVEA vulnerability in the Containerized Data Importer (CDI) for Kubernetes, identified as CVE-2026-17527, allows privilege escalation and data exfiltration through an improperly configured `cdi.kubevirt.io:view` ClusterRole, enabling attackers with partial access to clone and access data from any PersistentVolumeClaim in the cluster.
Kernel Local Privilege Escalation Vulnerability CVE-2026-17523
1 TTP 1 CVEA critical local privilege escalation (LPE) vulnerability, tracked as CVE-2026-17523 and identified as an Expired Pointer Dereference (CWE-825), exists within the kernel, primarily affecting Red Hat Enterprise Linux 8, enabling an unprivileged local user to execute arbitrary code within the kernel, leading to root privileges and full control over the compromised system.
Red Hat Advanced Cluster Management Vulnerability Allows Cluster-Admin Privilege Escalation
1 TTP 1 CVEA flaw exists in the cluster-proxy service-proxy component of Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE), allowing an authenticated hub principal to inject an Impersonate-Group header into proxied requests, bypassing validation, and leveraging the spoke ServiceAccount's unrestricted impersonation permissions to escalate privileges to cluster-admin on all managed clusters.
Red Hat Quay Vulnerability Allows Authenticated Remote Attacker to Bypass Security
1 TTPAn authenticated remote attacker can exploit a vulnerability in Red Hat Quay to bypass security measures, circumventing established security controls within the container registry.
CVE-2026-64611: libcupsfilters Denial of Service via Malformed Printer Advertisement
1 TTP 1 CVEA high-severity denial of service vulnerability, CVE-2026-64611, exists in the `cfIEEE1284NormalizeMakeModel()` function of libcupsfilters, allowing a network-adjacent attacker to cause sustained CPU consumption and system unresponsiveness by broadcasting a specially crafted printer advertisement with an empty model field in the IEEE-1284 device ID.
CVE-2026-16745: Authentication Bypass in Red Hat OpenShift AI odh-dashboard
4 TTPs 1 CVEA critical vulnerability, CVE-2026-16745, exists in the odh-dashboard web console component of Red Hat OpenShift AI (RHOAI), allowing a malicious actor within the cluster to bypass authentication by providing an arbitrary access token, leading to user impersonation and unauthorized access to the Kubernetes API, potentially resulting in arbitrary code execution, privilege escalation, and information disclosure.
Ansible Lightspeed VS Code Extension Command Injection Vulnerability (CVE-2026-44190)
1 TTP 1 CVEA command injection vulnerability (CVE-2026-44190, CWE-78) in the Ansible Lightspeed Visual Studio Code extension allows remote attackers to execute arbitrary commands on a user's system due to improper validation of the `ansible.python.activationScript` setting, leading to complete system control when a malicious project is opened.
Ansible: Local Code Execution Vulnerability
1 TTPA local attacker can exploit a vulnerability within Ansible software to execute arbitrary code on the affected system, potentially leading to further compromise or unauthorized actions on the host where Ansible is running.
Multiple Vulnerabilities in Red Hat Ansible Automation Platform
5 TTPsMultiple vulnerabilities exist in Red Hat Ansible Automation Platform, stemming from issues in components such as node-tar, linkify-it, protobufjs, brace-expansion, fast-uri, and DOMPurify. A remote, unauthenticated attacker can exploit these flaws to bypass security measures, perform Cross-Site Scripting (XSS) attacks, manipulate data, trigger Denial-of-Service (DoS) conditions, or execute arbitrary code on the affected system.
Red Hat Enterprise Linux Vulnerabilities Allow Privilege Escalation and DoS
4 TTPsMultiple vulnerabilities in Red Hat Enterprise Linux, affecting components such as sssd, glib, and c-ares, can be exploited by an attacker to gain administrator privileges, bypass security measures, manipulate data, and trigger a denial-of-service condition.
Unusual Child Process Execution by Web Servers on Linux
2 rules 5 TTPs 13 IOCsThis detection rule identifies suspicious child process executions originating from web server processes on Linux systems, indicating that attackers may have exploited web application vulnerabilities such as command injection or remote file inclusion to establish persistence or execute malicious commands.
Suspicious Command Execution via Linux Web Server
1 rule 14 TTPsThis brief describes how attackers exploit vulnerabilities in web applications to execute suspicious shell commands via web server processes on Linux, enabling persistence, discovery, credential access, and reverse shell establishment, which can lead to full system compromise and data exfiltration.
CVE-2026-16242: Konnectivity Proxy-Server Authentication Bypass
4 TTPs 1 CVEA critical authentication bypass vulnerability, CVE-2026-16242, exists in the Konnectivity proxy-server configuration for hosted control planes, allowing a remote unauthenticated attacker to connect as an agent and potentially proxy, inspect, modify, or drop control-plane-to-node traffic due to improper client certificate validation.
PipeWire Vulnerability CVE-2026-5674 Allows Sandbox Escape and Arbitrary Code Execution
4 TTPs 1 CVEA critical vulnerability, CVE-2026-5674, exists in PipeWire, a multimedia server, enabling an attacker to escape sandboxed applications like Flatpak by exploiting its PulseAudio compatibility layer to load a malicious library, leading to arbitrary code execution outside the sandbox and potential system compromise.
Red Hat OpenShift Container Platform Vulnerability Allows Security Bypass
1 TTPA vulnerability in the Red Hat OpenShift Container Platform allows a local attacker to bypass security controls, potentially leading to unauthorized access or further compromise of the platform.
Red Hat Quay: Multiple Vulnerabilities
3 TTPsMultiple vulnerabilities in Red Hat Quay allow a remote, authenticated attacker to execute arbitrary code and perform Server-Side Request Forgery (SSRF) attacks.
Feast Feature Server Denial of Service via Unauthenticated WebSocket Connections (CVE-2026-23538)
1 rule 1 TTP 1 CVEA vulnerability (CVE-2026-23538) exists in the Feast Feature Server's /ws/chat endpoint, allowing remote attackers to establish numerous unauthenticated, persistent WebSocket connections. This exploit, a form of resource exhaustion (CWE-770), consumes server resources like memory, CPU, and file descriptors, leading to a complete denial of service for legitimate users. Affected versions are those prior to 0.59.0.
Keycloak JWT Authorization Bypass via Disabled User Accounts (CVE-2026-1609)
1 TTP 1 CVEA vulnerability exists in Keycloak when its JSON Web Token (JWT) authorization grant preview feature is enabled, allowing a remote attacker with low privileges to exploit CVE-2026-1609 by presenting a valid assertion token from an external identity provider to obtain a JWT for a user account that has been disabled, thereby bypassing access controls and gaining unauthorized access to sensitive resources.
CVE-2026-12382 - AAP Gateway Envoy Proxy Authentication Bypass
2 TTPs 1 CVEA critical authentication bypass vulnerability (CVE-2026-12382) exists in the AAP Gateway Envoy proxy configuration within Red Hat Ansible Automation Platform 2 where the non-mTLS route to EDA event streams fails to remove the Subject HTTP header from client requests, allowing an unauthenticated remote attacker to inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.
Red Hat Enterprise Linux (pacemaker) Vulnerability Enables Denial of Service
1 TTPA vulnerability in Red Hat Enterprise Linux (pacemaker) allows a remote, unauthenticated attacker to perform a Denial of Service attack, potentially disrupting the availability of affected systems.
OpenShift GitOps Operator Vulnerability Allows Denial of Service via ClusterRole Name Collision
1 TTP 1 CVEA high-severity denial of service vulnerability, identified as CVE-2026-14251, exists in the OpenShift GitOps operator where a namespace-scoped Argo CD instance can trigger the deletion of a cluster-scoped Argo CD instance's ClusterRole by exploiting a name collision due to improper resource ownership validation.
Red Hat Enterprise Linux Plexus-Utils Vulnerability Allows Remote Code Execution
1 TTPA remote, unauthenticated attacker can exploit a vulnerability in Red Hat Enterprise Linux, specifically within the plexus-utils component, to execute arbitrary program code with user privileges, leading to system compromise.
Unauthenticated Remote Code Execution in Argo CD Repo-Server (CVE-2026-15416)
3 TTPs 1 CVEAn unauthenticated remote code execution vulnerability (CVE-2026-15416) exists in Argo CD's repo-server, the GitOps engine used by Red Hat OpenShift GitOps, allowing an attacker with network access to achieve RCE and deploy malicious Kubernetes resources, leading to potential cluster compromise.
CVE-2026-15584 Privilege Escalation in OpenShift incluster-checks Tool
1 TTP 1 CVEA privilege escalation vulnerability, CVE-2026-15584, in Red Hat OpenShift's incluster-checks tool allows users with standard edit roles to obtain root access on cluster nodes by exploiting privileged debug pods with host filesystem access created in the shared default namespace.
Multiple Vulnerabilities in Schneider Electric PowerChute Serial Shutdown
5 TTPs 5 CVEsMultiple vulnerabilities, including CVE-2026-2399, CVE-2026-2404, CVE-2026-2405, CVE-2026-2403, CVE-2026-2400, and CVE-2026-2401, in Schneider Electric PowerChute Serial Shutdown versions 1.4 and prior could allow attackers with adjacent network access and high privileges to overwrite critical system files via path traversal, forge or inject malicious log data, gain unauthorized account access through excessive authentication attempts, trigger denial-of-service conditions, or expose sensitive information.
Shai-Hulud Campaign Activity
25 IOCsTracking brief for the Shai-Hulud campaign; individual sightings are folded in as reported.
CVE-2026-59692: GStreamer DTLS Plugin Stack Buffer Overflow Leading to DoS
2 TTPs 1 CVEA stack buffer overflow vulnerability, CVE-2026-59692, exists in GStreamer's DTLS plugin, allowing a remote unauthenticated attacker to cause a denial of service by sending a crafted certificate with an oversized Subject Distinguished Name during a DTLS handshake, which the plugin prints into a fixed-size stack buffer without bounds checking, leading to a process crash.
CVE-2026-59691: GStreamer rfbsrc Heap Buffer Overflow Leads to DoS
1 TTP 1 CVEA heap buffer overflow vulnerability (CVE-2026-59691) exists in GStreamer's rfbsrc plugin, allowing a malicious RFB/VNC server to trigger an out-of-bounds heap write in connecting clients, leading to denial of service and potential memory corruption.
Multiple Vulnerabilities in Red Hat Enterprise Linux Components libsolv and aardvark-dns
3 TTPsMultiple vulnerabilities in Red Hat Enterprise Linux components libsolv and aardvark-dns could allow an attacker to perform a Denial of Service attack, manipulate data, or disclose confidential information.
Red Hat Enterprise Linux: Golang Component Vulnerability Enables Denial of Service
1 TTPA remote, unauthenticated attacker can exploit a vulnerability in Golang components within Red Hat OpenShift, Red Hat Ansible Automation Platform, and Red Hat Enterprise Linux to conduct a Denial of Service attack, leading to service disruption.
Red Hat Enterprise Linux (389-ds-base): Multiple Vulnerabilities Allow Code Execution and DoS
2 TTPsMultiple vulnerabilities in Red Hat Enterprise Linux and the 389-ds-base component allow a remote, authenticated attacker to execute arbitrary code or cause a Denial-of-Service condition.
Red Hat JBoss Enterprise Application Platform Cross-Site Scripting Vulnerability
1 TTPA remote, unauthenticated attacker can exploit a Cross-Site Scripting (XSS) vulnerability in the 'io.undertow.jastow' component of Red Hat JBoss Enterprise Application Platform, allowing injection of malicious scripts into web pages which can lead to session hijacking, data theft, or defacement.
Red Hat Enterprise Linux (python-pip) Vulnerability Allows Remote Code Execution
2 TTPsA remote authenticated attacker can exploit a vulnerability in Red Hat Enterprise Linux, specifically within its python-pip component, to overwrite arbitrary files and potentially achieve arbitrary code execution, allowing for system compromise through authenticated remote access.
Red Hat Enterprise Linux (perl-HTTP-Daemon): Remote Code Execution Vulnerability
2 TTPsA remote, unauthenticated attacker can exploit a vulnerability in the 'perl-HTTP-Daemon' component within Red Hat Enterprise Linux to execute arbitrary program code with the privileges of the affected service, potentially gaining control over the compromised system.
CVE-2026-14476: SSSD AD GPO Provider Path Traversal to Root File Write and Authentication Bypass
5 TTPs 1 CVEA path traversal vulnerability (CVE-2026-14476) in SSSD's Active Directory Group Policy Object (AD GPO) provider allows an authenticated attacker with AD GPO management access to write arbitrary files outside the GPO cache directory with root privileges, leading to Kerberos configuration injection and potential authentication bypass on Red Hat Enterprise Linux systems.
CVE-2026-11610: 389 Directory Server SASL Heap Buffer Overflow Leading to DoS
1 TTP 1 CVEA heap buffer overflow vulnerability (CVE-2026-11610) exists in the SASL I/O layer of 389 Directory Server (389-ds-base), active since version 1.3.2. An authenticated attacker can send a specially crafted, oversized LDAP UNBIND packet after a successful SASL bind with integrity protection. This causes approximately 2 megabytes of attacker-controlled data to overflow a 512-byte heap buffer in sasl_io_recv(), leading to a denial of service (server crash).
CVE-2026-58384: GIMP PSD Parser Integer Overflow Leads to RCE/DoS
2 TTPs 1 CVEAn integer overflow vulnerability (CVE-2026-58384) exists in GIMP's PSD parser within the `read_RLE_channel()` function, leading to undersized heap allocations that can cause subsequent heap memory corruption, potentially resulting in denial of service or arbitrary code execution.
CVE-2026-58380: GIMP PNM Parser Off-by-One Error Leads to RCE
1 CVEA high-severity off-by-one error, CVE-2026-58380, in GIMP's PNM file format parser (specifically the `pnmscanner_gettoken()` function) allows an attacker to corrupt memory by crafting a malicious PNM file, potentially leading to denial of service or arbitrary code execution when the file is opened.
Potential Proxy Execution via Systemd-run on Linux
1 rule 3 TTPsThis brief details how attackers may leverage the `systemd-run` utility on Linux systems for defense evasion and execution by running commands as detached, transient services or scopes to obscure their activities and parent-child process chains.
CVE-2026-9165 - Red Hat Advanced Cluster Security for Kubernetes Central Component Denial of Service
1 TTP 1 CVEAn authenticated denial of service vulnerability (CVE-2026-9165) exists in the Red Hat Advanced Cluster Security for Kubernetes (RHACS) Central component, allowing attackers with a valid API token to send deeply nested GraphQL queries that cause excessive resource consumption and render the management plane unavailable.
Red Hat JBoss Enterprise Application Platform: Multiple Vulnerabilities
5 TTPsMultiple vulnerabilities in Red Hat JBoss Enterprise Application Platform allow a remote, unauthenticated attacker to execute arbitrary code, perform cross-site scripting (XSS) attacks, disclose sensitive information, cause a denial of service, or bypass security mechanisms, posing a significant risk of system compromise and data exposure.
CVE-2026-58379: GIMP Heap Buffer Overflow in PSP Parser Allows RCE
3 TTPs 1 CVEA heap buffer overflow vulnerability (CVE-2026-58379) in GIMP's Paint Shop Pro (PSP) file format parser allows a remote attacker to achieve arbitrary code execution or cause a denial of service (DoS) by tricking a user into opening a specially crafted PSP image file, exploiting incorrect buffer size calculations when processing low bit-depth images.
Google Security Updates — July 2026
5 CVEs 41 IOCsRoundup of Google security advisories published in July 2026.
Microsoft Security Updates — July 2026
11 CVEs 354 IOCsRoundup of Microsoft security advisories published in July 2026.
Red Hat Cloud Services npm Packages Hijacked
2 rulesMultiple npm packages within the legitimate @redhat-cloud-services namespace have been hijacked with malicious code, posing a supply chain risk.
Red Hat npm Packages Compromised by Miasma Malware
2 rules 2 TTPsA supply chain attack compromised over 30 npm packages under Red Hat's '@redhat-cloud-services' namespace, distributing a credential-stealing malware variant named 'Miasma' that targets sensitive developer information.
Suspicious Command Execution via Web Server on Linux
2 rules 3 TTPsIdentifies suspicious command executions via a web server on Linux systems, which may suggest a vulnerability and remote shell access.
Red Hat Enterprise Linux (crun) Privilege Escalation Vulnerability
2 rules 1 TTPA local attacker can exploit a vulnerability in Red Hat Enterprise Linux (crun) to escalate their privileges, potentially gaining root access.
CIFSwitch Linux Kernel Local Privilege Escalation Vulnerability
2 rules 1 TTPThe CIFSwitch vulnerability in the Linux kernel allows an unprivileged user to forge CIFS authentication key descriptions, abuse the kernel's key request mechanism, and gain root privileges by loading a malicious NSS module.
OpenShift Router Vulnerability CVE-2026-46579: Mutual TLS Bypass via Header Injection
1 rule 2 TTPs 1 CVECVE-2026-46579 describes a vulnerability in the Red Hat OpenShift Router. When a Route is configured with `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend fails to remove `X-SSL-Client-*` headers from incoming requests, allowing unauthenticated attackers to bypass mutual TLS authentication and impersonate client certificate identities.
OpenShift Router SSRF via FQDN EndpointSlice (CVE-2026-42965)
1 rule 1 TTP 1 CVECVE-2026-42965 describes a server-side request forgery (SSRF) vulnerability in the OpenShift Router where a user with EndpointSlice write access can expose instance credentials by creating a service that proxies requests to a cloud metadata endpoint.
Red Hat Enterprise Linux Flatpak Multiple Vulnerabilities Allow Code Execution and File Deletion
2 rules 1 TTPAn authenticated attacker can exploit multiple vulnerabilities in the Flatpak package of Red Hat Enterprise Linux to execute arbitrary program code and delete files.
Red Hat OpenShift Tempo Vulnerabilities Allow Remote Exploitation
1 rule 3 TTPsMultiple vulnerabilities in Red Hat OpenShift Tempo allow an unauthenticated remote attacker to bypass security measures, disclose sensitive information, manipulate data, or cause a denial of service condition.
CVE-2026-44604: RPM rpmuncompress Command Injection Vulnerability
2 rules 1 TTP 1 CVEA command injection vulnerability (CVE-2026-44604) exists in the `rpmuncompress` utility of RPM; when extracting specially crafted ZIP, 7z, or GEM archives, an attacker can inject shell commands via a malicious top-level folder name, leading to arbitrary code execution as the user running the extraction.
Samba NTFS Reparse Point Vulnerability (CVE-2026-1933)
2 rules 1 TTP 1 CVECVE-2026-1933 describes a vulnerability in Samba's handling of NTFS-style reparse points on read-only shares, allowing authenticated users with filesystem write permissions to modify reparse point metadata and potentially alter SMB-visible file behavior.
CVE-2026-42013: gnutls Certificate Validation Bypass via Oversized SAN
2 rules 1 TTP 1 CVEA vulnerability in gnutls (CVE-2026-42013) allows a remote attacker to bypass certificate validation by providing an oversized Subject Alternative Name (SAN), causing the validation process to fall back to the Common Name (CN) field, potentially leading to spoofing or man-in-the-middle attacks.
KubeVirt virt-handler Symlink Vulnerability Leading to Container Escape (CVE-2026-7374)
2 rules 1 TTP 1 CVECVE-2026-7374 allows an authenticated OpenShift user with edit permissions in a single namespace to escalate privileges to full cluster control by exploiting improper symlink validation in KubeVirt's virt-handler component when connecting to VM console sockets.
CVE-2026-9064: 389-ds-base Unauthenticated Remote Denial-of-Service
2 rules 1 TTP 1 CVECVE-2026-9064 describes a denial-of-service vulnerability in 389-ds-base where an unauthenticated attacker can send a crafted LDAP request with excessive controls, causing excessive CPU consumption and heap allocation, leading to latency degradation, worker thread starvation, or out-of-memory termination.
Keycloak OIDC Implicit Flow Bypass Vulnerability (CVE-2026-7571)
2 rules 1 TTP 1 CVECVE-2026-7571 describes a vulnerability in Keycloak where a low-privilege user can bypass security controls intended to disable the implicit flow in OpenID Connect (OIDC) clients by manipulating client data during session restart, potentially exposing access tokens.
CVE-2026-7507: Keycloak Session Fixation Vulnerability in Login Actions Endpoints
2 rules 1 TTP 1 CVEA session fixation vulnerability in Keycloak's /login-actions/restart endpoint allows an unauthenticated attacker to hijack a user's session by crafting a malicious link that resets the authentication flow, potentially leading to account takeover.
Keycloak Open Redirect Vulnerability (CVE-2026-7504)
2 rules 1 TTP 1 CVEA vulnerability in Keycloak's URL validation allows attackers to redirect users to unauthorized URLs by exploiting discrepancies in the handling of the user-info component within URLs, potentially leading to sensitive information exposure.
Podman Vulnerability Allows File Manipulation
1 rule 1 TTPA remote, authenticated attacker can exploit a vulnerability in Podman to manipulate files on the host system.
Red Hat Enterprise Linux Valkey Vulnerabilities Lead to File Manipulation and Denial of Service
2 rules 1 TTPAn authenticated or anonymous attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux regarding Valkey to manipulate files or cause a denial-of-service condition.
Keycloak Security Bypass Vulnerability
2 rules 1 TTPAn authenticated remote attacker can exploit a vulnerability in Keycloak to bypass security measures.
Multiple Vulnerabilities in Red Hat Build of Quarkus
2 rules 2 TTPsAn authenticated or unauthenticated remote attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux and Quarkus to perform a denial of service attack, disclose sensitive information, or manipulate data.
Multiple Vulnerabilities in Red Hat Enterprise Linux and OpenShift Grafana Component
2 rules 3 TTPsA remote anonymous attacker can exploit multiple vulnerabilities in the Grafana component of Red Hat Enterprise Linux and OpenShift to execute arbitrary code, disclose confidential information, and cause a denial-of-service condition.
Red Hat Enterprise Linux Cloud-Init Privilege Escalation Vulnerability
1 rule 1 TTPA vulnerability in the cloud-init component of Red Hat Enterprise Linux allows an attacker from an adjacent network to gain administrator privileges.
Leveraging Linux Cgroups for Threat Detection and Investigation
2 rulesThis brief outlines how Linux cgroups, a kernel feature for resource management, can be repurposed to provide valuable telemetry for detecting malicious processes, particularly in systemd, Docker, and Kubernetes environments, aiding in investigations of server compromises.
Multiple Vulnerabilities in Kiali for Red Hat OpenShift Service Mesh
2 rules 4 TTPsAn anonymous remote attacker can exploit multiple vulnerabilities in Kiali for Red Hat OpenShift Service Mesh to gain extended privileges, bypass security measures, manipulate or disclose data, or cause a denial-of-service condition.
Red Hat Enterprise Linux Multiple Vulnerabilities Leading to RCE/DoS
2 rules 2 TTPsA remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux to execute arbitrary code or cause a denial-of-service condition.
Multiple Vulnerabilities in Red Hat Build of Keycloak
2 rules 5 TTPsMultiple vulnerabilities in Red Hat Build of Keycloak could allow an attacker to bypass authentication, gain elevated privileges, disclose sensitive information, cause a denial of service condition, execute arbitrary code, or manipulate data.
Red Hat Enterprise Linux (openEXR) Vulnerability Allows Code Execution
2 rules 1 TTPA remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux (openEXR) to execute arbitrary program code.
Multiple Vulnerabilities in Red Hat Hardened Images RPMs
2 rules 1 TTPA remote, anonymous attacker can exploit multiple vulnerabilities in Red Hat Hardened Images RPMs to cause a denial-of-service condition and possibly manipulate data or perform path traversal attacks.
Podman HyperV Machine Vulnerability Allows Arbitrary Code Execution with Administrator Privileges
2 rules 1 TTPA local attacker can exploit a vulnerability in Podman HyperV Machine to execute arbitrary program code with administrator privileges, leading to complete system compromise.
Dirty Frag Linux Kernel Local Privilege Escalation Vulnerability
2 rules 1 TTPThe Dirty Frag vulnerability (CVE-2026-43284 and CVE-2026-43500) is a Linux kernel local privilege escalation that allows an unprivileged local user to gain root privileges by exploiting flaws in the networking subsystem to overwrite protected file contents in the page cache.
Red Hat Build of Debezium for Red Hat Application Foundations Vulnerabilities Allow Code Execution
2 rules 1 TTPMultiple vulnerabilities in Red Hat Build of Debezium for Red Hat Application Foundations could allow an attacker to execute arbitrary code.
Multiple Vulnerabilities in Red Hat Enterprise Linux
2 rules 3 TTPsAn unauthenticated or authenticated remote attacker can exploit vulnerabilities in Red Hat Enterprise Linux to perform cross-site scripting, cause denial of service, or disclose sensitive information.
Red Hat OpenShift Service Mesh Multiple Vulnerabilities
2 rules 4 TTPsAn anonymous remote attacker can exploit multiple vulnerabilities in Red Hat OpenShift Service Mesh to manipulate files, disclose information, or cause a denial-of-service condition.
Dell Security Advisories Address Multiple Vulnerabilities
2 rulesDell published security advisories addressing vulnerabilities in APEX Cloud Platform, Automation Platform, Command | Monitor, CyberSense, NativeEdge Orchestrator, SmartFabric Manager, iDRAC, Disk Library, and PowerProtect Cyber Recovery, requiring users to apply necessary updates.
Red Hat Advanced Cluster Management and Multicluster Engine Vulnerability Allows Remote Code Execution or DoS
2 rules 2 TTPsA remote, authenticated attacker can exploit a vulnerability in Red Hat Advanced Cluster Management and Multicluster engine for Kubernetes to execute arbitrary program code or cause a denial of service condition.
Red Hat Hardened Images RPMs Fontconfig Vulnerability
2 rules 2 TTPsA local attacker can exploit a vulnerability in Red Hat Hardened Images RPMs to execute arbitrary code or cause a denial of service.
Multiple Vulnerabilities in Red Hat Hardened Images RPMs
2 rules 5 TTPsMultiple vulnerabilities in Red Hat Hardened Images RPMs can be exploited by an attacker to bypass security measures, escalate privileges, disclose sensitive information, manipulate data, or cause a denial-of-service condition.
Multiple Vulnerabilities in Red Hat Enterprise Linux and Satellite
2 rules 2 TTPsMultiple vulnerabilities in Red Hat Enterprise Linux and Red Hat Satellite could allow a remote, anonymous attacker to disclose information or execute arbitrary code.
Red Hat OpenShift Container Platform Security Bypass Vulnerability
2 rules 1 TTPA remote, authenticated attacker can exploit a vulnerability in Red Hat OpenShift Container Platform to bypass security measures.
Podman Desktop Vulnerability Allows Denial of Service and Information Disclosure
3 rules 2 TTPsA remote, anonymous attacker can exploit a vulnerability in Podman Desktop to perform a denial of service attack and disclose sensitive information.
Red Hat Enterprise Linux freeipmi Vulnerability Allows Code Execution
2 rules 4 TTPsA remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux freeipmi to cause a denial of service condition or memory corruption, potentially allowing arbitrary code execution.
Red Hat Enterprise Linux Vulnerability Allows Privilege Escalation and Code Execution
2 rules 2 TTPsA remote, anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux (python-wheel) to escalate privileges or execute arbitrary code.
Quarkus Vertx HTTP Authorization Bypass via Matrix Parameters
2 rules 2 TTPsQuarkus Vertx HTTP versions < 3.20.6.1, >= 3.21.0 and < 3.27.3.1, >= 3.30.0 and < 3.33.1.1, and >= 3.34.0 and < 3.35.1.1 are vulnerable to an authorization bypass where appending a semicolon and arbitrary text to the request URL allows unauthorized access to protected resources.
AAP Gateway Account Hijacking Vulnerability (CVE-2026-6266)
2 rules 1 TTP 1 CVECVE-2026-6266 allows a remote attacker to hijack user accounts in AAP gateway by manipulating the IDP-provided email during the user auto-linking process, potentially gaining unauthorized access, including administrative privileges.
CVE-2026-31431 'Copy Fail' Linux Kernel Privilege Escalation
2 rules 1 TTP 1 CVEThe 'Copy Fail' vulnerability (CVE-2026-31431) in the Linux kernel allows a local attacker to escalate privileges to root, potentially leading to container breakout and lateral movement in cloud environments.
GnuTLS DTLS Handshake Parsing Flaw (CVE-2026-33845)
2 rules 3 TTPs 1 CVEA flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read, potentially causing information disclosure or denial of service.
Local Privilege Escalation Vulnerability 'Copy Fail' in Linux Kernel
2 rules 1 TTP 1 CVEA local privilege escalation vulnerability, dubbed 'Copy Fail' (CVE-2026-31431), affects Linux kernels released since 2017, allowing an unprivileged local attacker to gain root permissions by exploiting a logic bug in the authencesn cryptographic template.
Multiple Vulnerabilities in Red Hat Enterprise Linux Fast Datapath
2 rules 4 TTPsA remote, anonymous attacker can exploit multiple vulnerabilities in Fast Datapath for Red Hat Enterprise Linux to perform a denial-of-service attack or disclose sensitive information.
Multiple Vulnerabilities in Red Hat Linux Kernel
2 rules 3 TTPs 5 CVEsMultiple vulnerabilities in the Red Hat Linux kernel allow for arbitrary code execution, privilege escalation, and remote denial of service.
Red Hat Enterprise Linux LibRaw Multiple Vulnerabilities Allow Code Execution or DoS
2 rules 2 TTPsMultiple vulnerabilities in Red Hat Enterprise Linux's LibRaw component allow a remote attacker to execute arbitrary code or cause a denial-of-service condition.
InstructLab Arbitrary Code Execution via Malicious HuggingFace Model
2 rules 1 TTP 1 CVEInstructLab is vulnerable to arbitrary code execution because the `linux_train.py` script hardcodes `trust_remote_code=True` when loading models from HuggingFace, allowing remote attackers to execute code by convincing a user to load a malicious model.
Red Hat Enterprise Linux File Manipulation Vulnerability
2 rules 2 TTPsAn authenticated remote attacker can exploit a vulnerability in Red Hat Enterprise Linux (CPython) to manipulate files.
Red Hat Enterprise Linux Quarkus Vulnerabilities Lead to Information Disclosure and Denial of Service
2 rules 2 TTPsMultiple vulnerabilities in Quarkus on Red Hat Enterprise Linux allow a remote attacker to disclose information or trigger a denial of service.
Red Hat Integration Camel for Spring Boot Multiple Vulnerabilities
2 rules 1 TTPAn anonymous remote attacker can exploit multiple vulnerabilities in Red Hat Integration Camel for Spring Boot to compromise confidentiality, availability, and integrity.
Unexpected Linux Auditd Daemon Shutdown
3 rules 1 TTPThis analytic detects unexpected shutdowns of the Linux auditd daemon, potentially indicating attempts to disable security monitoring and evade detection by attackers.
Linux Auditd Daemon Abort Detection
2 rules 1 TTPDetection of abnormal Linux audit daemon (auditd) termination via DAEMON_ABORT events, indicating potential auditing subsystem failure due to resource exhaustion, corruption, or malicious interference.
Linux Auditd Daemon (Re)Initialization Detection
3 rules 1 TTPDetection of Linux audit daemon (auditd) re-initialization events, which can indicate attempts to re-enable audit logging after evasion or restarts with modified rule sets.