Technology · Red Hat
Red Hat Enterprise Linux 7 vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 68 vulnerabilities in Red Hat Enterprise Linux 7: 0 in the last 7 days and 36 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-11770, was published on 31 July 2026.
- Last 7 days
- 0
- Last 90 days
- 36
- Critical, all time
- 2
- Exploited in the wild
- 0
About Red Hat Enterprise Linux 7
A distribution of the Linux operating system designed for business environments.
Latest Red Hat Enterprise Linux 7 vulnerabilities
- CVE-2026-11770: 389 Directory Server LDAP injection in CleanAllRUV replicationhighCVSS 7.5
- CVE-2026-58216: Samba KDC out-of-bounds read in kpasswd servicemediumCVSS 5.3
- CVE-2026-58218: Samba internal DNS server denial of service via TKEY cache exhaustionmediumCVSS 5.3
- CVE-2026-16527: Red Hat PCP auth bypass in pmproxy /store endpointhighCVSS 7.3
- CVE-2026-16526: Red Hat PCP privilege escalation in linux_sockets PMDAhighCVSS 8.8
- CVE-2026-16524: PCP linux_sockets PMDA command injection in network.persocket.filterhighCVSS 7.8
- CVE-2026-18107: CRIU privilege escalation via rseq critical section hijack during checkpointhighCVSS 7.8
- CVE-2026-16313: sg3_utils command injection via udev property injection in sg_inqhighCVSS 7.6
- CVE-2026-17072: GStreamer gst-plugins-good heap out-of-bounds read in Matroska demuxerlowCVSS 3.3
- CVE-2026-66759: GNOME GIMP out-of-bounds read in file-icns pluginhighCVSS 7.1
- CVE-2026-66757: GNOME GIMP integer overflow in file-sgi pluginmediumCVSS 5.5
- CVE-2026-15003: GNU Binutils heap overflow in linker XCOFF processingmediumCVSS 5.6
- CVE-2026-64611: OpenPrinting libcupsfilters infinite loop in cfIEEE1284NormalizeMakeModelhighCVSS 7.5
- CVE-2026-6390: GNU nano format string vulnerability in multi-buffer error handlingmediumCVSS 6.8
- CVE-2026-16552: systemd systemd-tmpfiles symlink-redirected arbitrary file overwritemediumCVSS 6.3
- CVE-2026-16473: BlueZ sbc heap out-of-bounds read in SBC frame decodermediumCVSS 4.3
- CVE-2026-16517: libarchive signed integer overflow in ZIP writerlowCVSS 2.9
- CVE-2026-15588: GNOME GLib denial of service in GDBus authenticationmediumCVSS 5.3
- CVE-2026-3842: QEMU out-of-bounds write in hyperv/syndbg memory mappinghighCVSS 7.8
- CVE-2026-15779: Samba pam_winbind denial of service via root directory chownmediumCVSS 6.1
- CVE-2026-14476: SSSD path traversal in AD GPO providerhighCVSS 8
- CVE-2026-58380: GNOME GIMP stack buffer overflow in PNM file parserhighCVSS 7.3
- CVE-2026-14612: FreeIPA ipa-otpd off-by-one errors in OAuth2 handlermediumCVSS 4.2
- CVE-2026-58381: GNOME GIMP double-free in PSP file format parsermediumCVSS 6.1
- CVE-2026-58016: GNOME GLib out-of-bounds read in D-Bus introspection XML parsinghighCVSS 7.5
Most severe Red Hat Enterprise Linux 7 vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-43125: Linux Kernel buffer overflow in dlm_search_rsb_treecriticalCVSS 9.8EPSS 0.5%
- CVE-2026-20911: LibRaw heap buffer overflow in HuffTable::initvalcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-16526: Red Hat PCP privilege escalation in linux_sockets PMDAhighCVSS 8.8
- CVE-2016-7543: GNU Bash privilege escalation via SHELLOPTS and PS4 variableshighCVSS 8.4
- CVE-2025-14523: GNOME libsoup HTTP request smuggling via duplicate Host headershighCVSS 8.2EPSS 0.5%
- CVE-2026-24660: LibRaw heap buffer overflow in x3f_load_huffmanhighCVSS 8.1EPSS 0.5%
- CVE-2026-14476: SSSD path traversal in AD GPO providerhighCVSS 8
- CVE-2025-6018: SUSE and Red Hat PAM local privilege escalation in pam-confighighCVSS 7.8EPSS 1.0%
- CVE-2025-7425: GNOME libxslt heap use-after-free in attribute managementhighCVSS 7.8EPSS 0.3%
- CVE-2026-12505: Samba cifs-utils privilege escalation in cifs.upcallhighCVSS 7.8EPSS 0.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 14 | 0 | |
| 6 Jul 2026 | 2 | 0 | |
| 13 Jul 2026 | 2 | 0 | |
| 20 Jul 2026 | 6 | 0 | |
| 27 Jul 2026 | 12 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/enterprise-linux-7.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Red Hat Enterprise Linux 7 vulnerabilities", https://junglewise.ai/threats/technologies/enterprise-linux-7, 26 September 2026.