Technology · Red Hat
Red Hat Enterprise Linux 9 vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 146 vulnerabilities in Red Hat Enterprise Linux 9: 0 in the last 7 days and 64 in the last 90 days, 5 of them critical and 0 exploited in the wild. The most recent, CVE-2026-11861, was published on 20 August 2026.
- Last 7 days
- 0
- Last 90 days
- 64
- Critical, all time
- 5
- Exploited in the wild
- 0
About Red Hat Enterprise Linux 9
A Linux distribution developed by Red Hat for enterprise environments.
Latest Red Hat Enterprise Linux 9 vulnerabilities
- CVE-2026-11861: FreeIPA TGS impersonation authentication bypass in trust relationshipscriticalCVSS 9.6EPSS 0.2%
- CVE-2026-58216: Samba KDC out-of-bounds read in kpasswd servicemediumCVSS 5.3
- CVE-2026-58218: Samba internal DNS server denial of service via TKEY cache exhaustionmediumCVSS 5.3
- CVE-2026-16527: Red Hat PCP auth bypass in pmproxy /store endpointhighCVSS 7.3
- CVE-2026-16526: Red Hat PCP privilege escalation in linux_sockets PMDAhighCVSS 8.8
- CVE-2026-16524: PCP linux_sockets PMDA command injection in network.persocket.filterhighCVSS 7.8
- CVE-2026-18107: CRIU privilege escalation via rseq critical section hijack during checkpointhighCVSS 7.8
- CVE-2026-16313: sg3_utils command injection via udev property injection in sg_inqhighCVSS 7.6
- CVE-2026-17072: GStreamer gst-plugins-good heap out-of-bounds read in Matroska demuxerlowCVSS 3.3
- CVE-2026-66759: GNOME GIMP out-of-bounds read in file-icns pluginhighCVSS 7.1
- CVE-2026-66757: GNOME GIMP integer overflow in file-sgi pluginmediumCVSS 5.5
- CVE-2026-16743: freedesktop.org accountsservice arbitrary file read in SetIconFilemediumCVSS 5.5
- CVE-2026-16730: dbus-broker denial of service via file-descriptor exhaustionmediumCVSS 5.5
- CVE-2026-12353: Red Hat Certificate System memory leak in TLS endpointmediumCVSS 5.3
- CVE-2026-64611: OpenPrinting libcupsfilters infinite loop in cfIEEE1284NormalizeMakeModelhighCVSS 7.5
- CVE-2026-6390: GNU nano format string vulnerability in multi-buffer error handlingmediumCVSS 6.8
- CVE-2026-16552: systemd systemd-tmpfiles symlink-redirected arbitrary file overwritemediumCVSS 6.3
- CVE-2026-16473: BlueZ sbc heap out-of-bounds read in SBC frame decodermediumCVSS 4.3
- CVE-2026-16517: libarchive signed integer overflow in ZIP writerlowCVSS 2.9
- CVE-2026-16493: Red Hat ansible-core argument injection in ansible-galaxy collection installhighCVSS 7.8
- CVE-2026-59850: libssh use-after-free in channel data callbacksmediumCVSS 4.3
- CVE-2026-59848: libssh denial of service via memory exhaustion in SFTP clientmediumCVSS 5.3
- CVE-2026-59847: libssh integrity protection bypass in OpenSSL AES-GCM backendmediumCVSS 5.9
- CVE-2026-59846: libssh shell metacharacter injection in ProxyCommand username expansionlowCVSS 3.9
- CVE-2026-59845: libssh denial of service via unchecked fork failure in ProxyCommandmediumCVSS 5.3
Most severe Red Hat Enterprise Linux 9 vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-33937: Handlebars.js remote code execution via AST type confusion in compilecriticalCVSS 9.8EPSS 1.7%
- CVE-2026-43125: Linux Kernel buffer overflow in dlm_search_rsb_treecriticalCVSS 9.8EPSS 0.5%
- CVE-2026-14544: HP HPLIP integer overflow in hpcups processing pathcriticalCVSS 9.8
- CVE-2026-11861: FreeIPA TGS impersonation authentication bypass in trust relationshipscriticalCVSS 9.6EPSS 0.2%
- CVE-2026-42216: AcademySoftwareFoundation OpenEXR out-of-bounds read in IDManifestcriticalCVSS 9.1EPSS 0.4%
- CVE-2025-66287: WebKitGTK buffer overflow via malicious web contenthighCVSS 8.8EPSS 0.4%
- CVE-2026-41142: AcademySoftwareFoundation OpenEXR heap OOB write in ImageChannel::resizehighCVSS 8.8EPSS 0.3%
- CVE-2026-16526: Red Hat PCP privilege escalation in linux_sockets PMDAhighCVSS 8.8
- CVE-2026-5674: PipeWire sandbox escape via PulseAudio compatibility layerhighCVSS 8.8
- CVE-2025-8067: storaged-project udisks privilege escalation in D-BUS loop device handlerhighCVSS 8.5EPSS 0.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 19 | 1 | |
| 6 Jul 2026 | 5 | 0 | |
| 13 Jul 2026 | 5 | 0 | |
| 20 Jul 2026 | 24 | 0 | |
| 27 Jul 2026 | 10 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 1 | 1 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/enterprise-linux-9.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Red Hat Enterprise Linux 9 vulnerabilities", https://junglewise.ai/threats/technologies/enterprise-linux-9, 26 September 2026.