{"schema_version":1,"title":"Red Hat Enterprise Linux 7 vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 68 vulnerabilities in Red Hat Enterprise Linux 7: 0 in the last 7 days and 36 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-11770, was published on 31 July 2026.","url":"https://junglewise.ai/threats/technologies/enterprise-linux-7","json_url":"https://junglewise.ai/threats/technologies/enterprise-linux-7.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/enterprise-linux-7","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":29,"all_time":68,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":36,"last_365_days":60},"latest":[{"cve":"CVE-2026-11770","cvss":7.5,"slug":"cve-2026-11770-389-directory-server-ldap-injection-in-cleanallruv-replication","title":"389 Directory Server LDAP injection in CleanAllRUV replication","severity":"high","exploited":false,"published_at":"2026-07-31T10:16:44.72+00:00","url":"https://junglewise.ai/threats/cve-2026-11770-389-directory-server-ldap-injection-in-cleanallruv-replication"},{"cve":"CVE-2026-58216","cvss":5.3,"slug":"cve-2026-58216-samba-kdc-out-of-bounds-read-in-kpasswd-service","title":"Samba KDC out-of-bounds read in kpasswd service","severity":"medium","exploited":false,"published_at":"2026-07-30T16:17:14.767+00:00","url":"https://junglewise.ai/threats/cve-2026-58216-samba-kdc-out-of-bounds-read-in-kpasswd-service"},{"cve":"CVE-2026-58218","cvss":5.3,"slug":"cve-2026-58218-samba-internal-dns-server-denial-of-service-via-tkey-cache","title":"Samba internal DNS server denial of service via TKEY cache exhaustion","severity":"medium","exploited":false,"published_at":"2026-07-30T14:17:00.307+00:00","url":"https://junglewise.ai/threats/cve-2026-58218-samba-internal-dns-server-denial-of-service-via-tkey-cache"},{"cve":"CVE-2026-16527","cvss":7.3,"slug":"cve-2026-16527-red-hat-pcp-auth-bypass-in-pmproxy-store-endpoint","title":"Red Hat PCP auth bypass in pmproxy /store endpoint","severity":"high","exploited":false,"published_at":"2026-07-30T06:25:02.813+00:00","url":"https://junglewise.ai/threats/cve-2026-16527-red-hat-pcp-auth-bypass-in-pmproxy-store-endpoint"},{"cve":"CVE-2026-16526","cvss":8.8,"slug":"cve-2026-16526-red-hat-pcp-privilege-escalation-in-linux-sockets-pmda","title":"Red Hat PCP privilege escalation in linux_sockets PMDA","severity":"high","exploited":false,"published_at":"2026-07-30T06:25:02.663+00:00","url":"https://junglewise.ai/threats/cve-2026-16526-red-hat-pcp-privilege-escalation-in-linux-sockets-pmda"},{"cve":"CVE-2026-16524","cvss":7.8,"slug":"cve-2026-16524-pcp-linux-sockets-pmda-command-injection-in-network-persocket","title":"PCP linux_sockets PMDA command injection in network.persocket.filter","severity":"high","exploited":false,"published_at":"2026-07-30T06:25:02.46+00:00","url":"https://junglewise.ai/threats/cve-2026-16524-pcp-linux-sockets-pmda-command-injection-in-network-persocket"},{"cve":"CVE-2026-18107","cvss":7.8,"slug":"cve-2026-18107-criu-privilege-escalation-via-rseq-critical-section-hijack-during","title":"CRIU privilege escalation via rseq critical section hijack during checkpoint","severity":"high","exploited":false,"published_at":"2026-07-28T19:17:32.42+00:00","url":"https://junglewise.ai/threats/cve-2026-18107-criu-privilege-escalation-via-rseq-critical-section-hijack-during"},{"cve":"CVE-2026-16313","cvss":7.6,"slug":"cve-2026-16313-sg3-utils-command-injection-via-udev-property-injection-in-sg-inq","title":"sg3_utils command injection via udev property injection in sg_inq","severity":"high","exploited":false,"published_at":"2026-07-28T17:16:37.807+00:00","url":"https://junglewise.ai/threats/cve-2026-16313-sg3-utils-command-injection-via-udev-property-injection-in-sg-inq"},{"cve":"CVE-2026-17072","cvss":3.3,"slug":"cve-2026-17072-gstreamer-gst-plugins-good-heap-out-of-bounds-read-in-matroska","title":"GStreamer gst-plugins-good heap out-of-bounds read in Matroska demuxer","severity":"low","exploited":false,"published_at":"2026-07-28T11:17:02.433+00:00","url":"https://junglewise.ai/threats/cve-2026-17072-gstreamer-gst-plugins-good-heap-out-of-bounds-read-in-matroska"},{"cve":"CVE-2026-66759","cvss":7.1,"slug":"cve-2026-66759-gnome-gimp-out-of-bounds-read-in-file-icns-plugin","title":"GNOME GIMP out-of-bounds read in file-icns plugin","severity":"high","exploited":false,"published_at":"2026-07-27T19:17:23.747+00:00","url":"https://junglewise.ai/threats/cve-2026-66759-gnome-gimp-out-of-bounds-read-in-file-icns-plugin"},{"cve":"CVE-2026-66757","cvss":5.5,"slug":"cve-2026-66757-gnome-gimp-integer-overflow-in-file-sgi-plugin","title":"GNOME GIMP integer overflow in file-sgi plugin","severity":"medium","exploited":false,"published_at":"2026-07-27T19:17:23.473+00:00","url":"https://junglewise.ai/threats/cve-2026-66757-gnome-gimp-integer-overflow-in-file-sgi-plugin"},{"cve":"CVE-2026-15003","cvss":5.6,"slug":"cve-2026-15003-gnu-binutils-heap-overflow-in-linker-xcoff-processing","title":"GNU Binutils heap overflow in linker XCOFF processing","severity":"medium","exploited":false,"published_at":"2026-07-27T14:16:51.473+00:00","url":"https://junglewise.ai/threats/cve-2026-15003-gnu-binutils-heap-overflow-in-linker-xcoff-processing"},{"cve":"CVE-2026-64611","cvss":7.5,"slug":"cve-2026-64611-openprinting-libcupsfilters-infinite-loop-in","title":"OpenPrinting libcupsfilters infinite loop in cfIEEE1284NormalizeMakeModel","severity":"high","exploited":false,"published_at":"2026-07-23T11:16:40.68+00:00","url":"https://junglewise.ai/threats/cve-2026-64611-openprinting-libcupsfilters-infinite-loop-in"},{"cve":"CVE-2026-6390","cvss":6.8,"slug":"cve-2026-6390-gnu-nano-format-string-vulnerability-in-multi-buffer-error","title":"GNU nano format string vulnerability in multi-buffer error handling","severity":"medium","exploited":false,"published_at":"2026-07-23T05:16:38.36+00:00","url":"https://junglewise.ai/threats/cve-2026-6390-gnu-nano-format-string-vulnerability-in-multi-buffer-error"},{"cve":"CVE-2026-16552","cvss":6.3,"slug":"cve-2026-16552-systemd-systemd-tmpfiles-symlink-redirected-arbitrary-file","title":"systemd systemd-tmpfiles symlink-redirected arbitrary file overwrite","severity":"medium","exploited":false,"published_at":"2026-07-22T16:17:16.653+00:00","url":"https://junglewise.ai/threats/cve-2026-16552-systemd-systemd-tmpfiles-symlink-redirected-arbitrary-file"},{"cve":"CVE-2026-16473","cvss":4.3,"slug":"cve-2026-16473-bluez-sbc-heap-out-of-bounds-read-in-sbc-frame-decoder","title":"BlueZ sbc heap out-of-bounds read in SBC frame decoder","severity":"medium","exploited":false,"published_at":"2026-07-22T11:16:50.097+00:00","url":"https://junglewise.ai/threats/cve-2026-16473-bluez-sbc-heap-out-of-bounds-read-in-sbc-frame-decoder"},{"cve":"CVE-2026-16517","cvss":2.9,"slug":"cve-2026-16517-libarchive-signed-integer-overflow-in-zip-writer","title":"libarchive signed integer overflow in ZIP writer","severity":"low","exploited":false,"published_at":"2026-07-21T23:17:00.587+00:00","url":"https://junglewise.ai/threats/cve-2026-16517-libarchive-signed-integer-overflow-in-zip-writer"},{"cve":"CVE-2026-15588","cvss":5.3,"slug":"cve-2026-15588-gnome-glib-denial-of-service-in-gdbus-authentication","title":"GNOME GLib denial of service in GDBus authentication","severity":"medium","exploited":false,"published_at":"2026-07-20T12:17:55.22+00:00","url":"https://junglewise.ai/threats/cve-2026-15588-gnome-glib-denial-of-service-in-gdbus-authentication"},{"cve":"CVE-2026-3842","cvss":7.8,"slug":"cve-2026-3842-qemu-out-of-bounds-write-in-hyperv-syndbg-memory-mapping","title":"QEMU out-of-bounds write in hyperv/syndbg memory mapping","severity":"high","exploited":false,"published_at":"2026-07-16T01:16:30.697+00:00","url":"https://junglewise.ai/threats/cve-2026-3842-qemu-out-of-bounds-write-in-hyperv-syndbg-memory-mapping"},{"cve":"CVE-2026-15779","cvss":6.1,"slug":"cve-2026-15779-samba-pam-winbind-denial-of-service-via-root-directory-chown","title":"Samba pam_winbind denial of service via root directory chown","severity":"medium","exploited":false,"published_at":"2026-07-15T13:17:03.65+00:00","url":"https://junglewise.ai/threats/cve-2026-15779-samba-pam-winbind-denial-of-service-via-root-directory-chown"},{"cve":"CVE-2026-14476","cvss":8,"slug":"cve-2026-14476-sssd-path-traversal-in-ad-gpo-provider","title":"SSSD path traversal in AD GPO provider","severity":"high","exploited":false,"published_at":"2026-07-07T10:16:39.993+00:00","url":"https://junglewise.ai/threats/cve-2026-14476-sssd-path-traversal-in-ad-gpo-provider"},{"cve":"CVE-2026-58380","cvss":7.3,"slug":"cve-2026-58380-gnome-gimp-stack-buffer-overflow-in-pnm-file-parser","title":"GNOME GIMP stack buffer overflow in PNM file parser","severity":"high","exploited":false,"published_at":"2026-07-06T15:16:40.02+00:00","url":"https://junglewise.ai/threats/cve-2026-58380-gnome-gimp-stack-buffer-overflow-in-pnm-file-parser"},{"cve":"CVE-2026-14612","cvss":4.2,"slug":"cve-2026-14612-freeipa-ipa-otpd-off-by-one-errors-in-oauth2-handler","title":"FreeIPA ipa-otpd off-by-one errors in OAuth2 handler","severity":"medium","exploited":false,"published_at":"2026-07-03T16:16:54.47+00:00","url":"https://junglewise.ai/threats/cve-2026-14612-freeipa-ipa-otpd-off-by-one-errors-in-oauth2-handler"},{"cve":"CVE-2026-58381","cvss":6.1,"slug":"cve-2026-58381-gnome-gimp-double-free-in-psp-file-format-parser","title":"GNOME GIMP double-free in PSP file format parser","severity":"medium","exploited":false,"published_at":"2026-07-02T20:17:06.17+00:00","url":"https://junglewise.ai/threats/cve-2026-58381-gnome-gimp-double-free-in-psp-file-format-parser"},{"cve":"CVE-2026-58016","cvss":7.5,"slug":"cve-2026-58016-gnome-glib-out-of-bounds-read-in-d-bus-introspection-xml-parsing","title":"GNOME GLib out-of-bounds read in D-Bus introspection XML parsing","severity":"high","exploited":false,"published_at":"2026-06-30T13:19:17.84+00:00","url":"https://junglewise.ai/threats/cve-2026-58016-gnome-glib-out-of-bounds-read-in-d-bus-introspection-xml-parsing"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":14},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":12},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Red Hat Enterprise Linux 9","slug":"enterprise-linux-9","vulnerabilities":146,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-9"},{"name":"Red Hat Enterprise Linux 10","slug":"enterprise-linux-10","vulnerabilities":140,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-10"},{"name":"Red Hat Enterprise Linux 8","slug":"enterprise-linux-8","vulnerabilities":132,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-8"},{"name":"Red Hat Enterprise Linux 6","slug":"enterprise-linux-6","vulnerabilities":55,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-6"},{"name":"Red Hat Build of Keycloak","slug":"red-hat-build-of-keycloak","vulnerabilities":54,"url":"https://junglewise.ai/threats/technologies/red-hat-build-of-keycloak"},{"name":"Red Hat Keycloak","slug":"build-of-keycloak","vulnerabilities":48,"url":"https://junglewise.ai/threats/technologies/build-of-keycloak"},{"name":"Red Hat Enterprise Linux AppStream","slug":"enterprise-linux-appstream","vulnerabilities":46,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-appstream"},{"name":"Red Hat OpenShift Container Platform 4","slug":"openshift-container-platform-4","vulnerabilities":36,"url":"https://junglewise.ai/threats/technologies/openshift-container-platform-4"},{"name":"Red Hat Developer Hub","slug":"developer-hub","vulnerabilities":28,"url":"https://junglewise.ai/threats/technologies/developer-hub"},{"name":"Red Hat Multicluster Global Hub","slug":"multicluster-global-hub","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/multicluster-global-hub"},{"name":"Red Hat AI Inference Server","slug":"ai-inference-server","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/ai-inference-server"},{"name":"Red Hat Enterprise Linux 9.0","slug":"enterprise-linux-9-0","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-9-0"}],"technology":{"hub":true,"name":"Red Hat Enterprise Linux 7","slug":"enterprise-linux-7","vendor":{"name":"Red Hat","slug":"red-hat","url":"https://junglewise.ai/threats/vendors/red-hat"},"aliases":["red-hat-enterprise-linux-7"],"category":"operating-system","homepage":"https://www.redhat.com/en/technologies/linux-platforms/enterprise-linux","description":"A distribution of the Linux operating system designed for business environments.","url":"https://junglewise.ai/threats/technologies/enterprise-linux-7"},"most_severe":[{"cve":"CVE-2026-43125","cvss":9.8,"epss":0.0054,"slug":"cve-2026-43125-linux-kernel-buffer-overflow-in-dlm-search-rsb-tree","title":"Linux Kernel buffer overflow in dlm_search_rsb_tree","severity":"critical","exploited":false,"published_at":"2026-05-06T12:16:29.45+00:00","url":"https://junglewise.ai/threats/cve-2026-43125-linux-kernel-buffer-overflow-in-dlm-search-rsb-tree"},{"cve":"CVE-2026-20911","cvss":9.8,"epss":0.0049,"slug":"cve-2026-20911-libraw-heap-buffer-overflow-in-hufftable-initval","title":"LibRaw heap buffer overflow in HuffTable::initval","severity":"critical","exploited":false,"published_at":"2026-04-07T15:17:35.467+00:00","url":"https://junglewise.ai/threats/cve-2026-20911-libraw-heap-buffer-overflow-in-hufftable-initval"},{"cve":"CVE-2026-16526","cvss":8.8,"slug":"cve-2026-16526-red-hat-pcp-privilege-escalation-in-linux-sockets-pmda","title":"Red Hat PCP privilege escalation in linux_sockets PMDA","severity":"high","exploited":false,"published_at":"2026-07-30T06:25:02.663+00:00","url":"https://junglewise.ai/threats/cve-2026-16526-red-hat-pcp-privilege-escalation-in-linux-sockets-pmda"},{"cve":"CVE-2016-7543","cvss":8.4,"slug":"cve-2016-7543-gnu-bash-privilege-escalation-via-shellopts-and-ps4-variables","title":"GNU Bash privilege escalation via SHELLOPTS and PS4 variables","severity":"high","exploited":false,"published_at":"2017-01-19T20:59:00.47+00:00","url":"https://junglewise.ai/threats/cve-2016-7543-gnu-bash-privilege-escalation-via-shellopts-and-ps4-variables"},{"cve":"CVE-2025-14523","cvss":8.2,"epss":0.005,"slug":"cve-2025-14523-gnome-libsoup-http-request-smuggling-via-duplicate-host-headers","title":"GNOME libsoup HTTP request smuggling via duplicate Host headers","severity":"high","exploited":false,"published_at":"2025-12-11T13:15:58.983+00:00","url":"https://junglewise.ai/threats/cve-2025-14523-gnome-libsoup-http-request-smuggling-via-duplicate-host-headers"},{"cve":"CVE-2026-24660","cvss":8.1,"epss":0.0046,"slug":"cve-2026-24660-libraw-heap-buffer-overflow-in-x3f-load-huffman","title":"LibRaw heap buffer overflow in x3f_load_huffman","severity":"high","exploited":false,"published_at":"2026-04-07T15:17:37.213+00:00","url":"https://junglewise.ai/threats/cve-2026-24660-libraw-heap-buffer-overflow-in-x3f-load-huffman"},{"cve":"CVE-2026-14476","cvss":8,"slug":"cve-2026-14476-sssd-path-traversal-in-ad-gpo-provider","title":"SSSD path traversal in AD GPO provider","severity":"high","exploited":false,"published_at":"2026-07-07T10:16:39.993+00:00","url":"https://junglewise.ai/threats/cve-2026-14476-sssd-path-traversal-in-ad-gpo-provider"},{"cve":"CVE-2025-6018","cvss":7.8,"epss":0.0096,"slug":"cve-2025-6018-suse-and-red-hat-pam-local-privilege-escalation-in-pam-config","title":"SUSE and Red Hat PAM local privilege escalation in pam-config","severity":"high","exploited":false,"published_at":"2025-07-23T15:15:34.81+00:00","url":"https://junglewise.ai/threats/cve-2025-6018-suse-and-red-hat-pam-local-privilege-escalation-in-pam-config"},{"cve":"CVE-2025-7425","cvss":7.8,"epss":0.0034,"slug":"cve-2025-7425-gnome-libxslt-heap-use-after-free-in-attribute-management","title":"GNOME libxslt heap use-after-free in attribute management","severity":"high","exploited":false,"published_at":"2025-07-10T14:15:27.877+00:00","url":"https://junglewise.ai/threats/cve-2025-7425-gnome-libxslt-heap-use-after-free-in-attribute-management"},{"cve":"CVE-2026-12505","cvss":7.8,"epss":0.0012,"slug":"cve-2026-12505-samba-cifs-utils-privilege-escalation-in-cifs-upcall","title":"Samba cifs-utils privilege escalation in cifs.upcall","severity":"high","exploited":false,"published_at":"2026-06-18T04:16:44.85+00:00","url":"https://junglewise.ai/threats/cve-2026-12505-samba-cifs-utils-privilege-escalation-in-cifs-upcall"}],"generated_at":"2026-09-26T17:07:00.185783+00:00"}