Technology · Red Hat
Red Hat OpenShift Container Platform 4 vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 36 vulnerabilities in Red Hat OpenShift Container Platform 4: 0 in the last 7 days and 17 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-58216, was published on 30 July 2026.
- Last 7 days
- 0
- Last 90 days
- 17
- Critical, all time
- 0
- Exploited in the wild
- 0
About Red Hat OpenShift Container Platform 4
A platform-as-a-service based on Kubernetes for deploying and managing containerized applications.
Latest Red Hat OpenShift Container Platform 4 vulnerabilities
- CVE-2026-58216: Samba KDC out-of-bounds read in kpasswd servicemediumCVSS 5.3
- CVE-2026-58218: Samba internal DNS server denial of service via TKEY cache exhaustionmediumCVSS 5.3
- CVE-2026-16527: Red Hat PCP auth bypass in pmproxy /store endpointhighCVSS 7.3
- CVE-2026-16526: Red Hat PCP privilege escalation in linux_sockets PMDAhighCVSS 8.8
- CVE-2026-18107: CRIU privilege escalation via rseq critical section hijack during checkpointhighCVSS 7.8
- CVE-2026-49332: OpenShift oauth-proxy identity impersonation via header smugglinghighCVSS 8.5
- CVE-2026-6390: GNU nano format string vulnerability in multi-buffer error handlingmediumCVSS 6.8
- CVE-2026-16517: libarchive signed integer overflow in ZIP writerlowCVSS 2.9
- CVE-2026-16445: Red Hat dracut command injection via DHCP optionshighCVSS 7.5
- CVE-2026-16461: rpcbind rpcinfo stack buffer overflow in rpcbdumpmediumCVSS 6.5
- CVE-2026-15812: kronosnet ACL bypass via link ID spoofing on unencrypted dynamic linksmediumCVSS 4.8
- CVE-2026-15811: Kronosnet improper memory clearing in cryptographic configurationmediumCVSS 5.8
- CVE-2026-16277: Red Hat rpcbind stack buffer overflow in rpcinfo utilitymediumCVSS 6.5
- CVE-2026-15813: kronosnet heap corruption in packet de-fragmentation enginemediumCVSS 6.5
- CVE-2026-14476: SSSD path traversal in AD GPO providerhighCVSS 8
- CVE-2026-13757: p11-kit stack exhaustion via uncontrolled recursion in RPC attribute parsingmediumCVSS 6.2
- CVE-2026-13595: util-linux libblkid heap use-after-free in nested partition probingmediumCVSS 6.8
- CVE-2026-55653: OpenSSH double free in DH-GEX client during FIPS validationmediumCVSS 4.3
- CVE-2026-12725: Dnsmasq heap buffer overflow in log_query functionmediumCVSS 5.9
- CVE-2026-54100: Red Hat WMCO improper SSH host key verification in OpenShifthighCVSS 8.3
- CVE-2026-54099: Red Hat WMCO privilege escalation in WICD CSR auto-approverhighCVSS 8.8
- CVE-2026-3195: QEMU heap overflow in virtio-snd devicehighCVSS 7.4
- CVE-2026-12505: Samba cifs-utils privilege escalation in cifs.upcallhighCVSS 7.8EPSS 0.1%
- CVE-2026-44289: protobufjs uncontrolled recursion in protobuf decodinghighCVSS 7.5EPSS 0.7%
- CVE-2026-43133: Linux Kernel KVM incorrect state handling in nSVM VMLOAD/VMSAVE emulationhighCVSS 7.9EPSS 0.1%
Most severe Red Hat OpenShift Container Platform 4 vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-16526: Red Hat PCP privilege escalation in linux_sockets PMDAhighCVSS 8.8
- CVE-2026-54099: Red Hat WMCO privilege escalation in WICD CSR auto-approverhighCVSS 8.8
- CVE-2026-49332: OpenShift oauth-proxy identity impersonation via header smugglinghighCVSS 8.5
- CVE-2026-54100: Red Hat WMCO improper SSH host key verification in OpenShifthighCVSS 8.3
- CVE-2026-41316: Ruby ERB arbitrary code execution via deserialization guard bypasshighCVSS 8.1EPSS 0.5%
- CVE-2026-43003: OpenStack Ironic Python Agent command injection via malicious imagehighCVSS 8EPSS 1.1%
- CVE-2026-14476: SSSD path traversal in AD GPO providerhighCVSS 8
- CVE-2026-43133: Linux Kernel KVM incorrect state handling in nSVM VMLOAD/VMSAVE emulationhighCVSS 7.9EPSS 0.1%
- CVE-2026-12505: Samba cifs-utils privilege escalation in cifs.upcallhighCVSS 7.8EPSS 0.1%
- CVE-2026-18107: CRIU privilege escalation via rseq critical section hijack during checkpointhighCVSS 7.8
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 2 | 0 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 8 | 0 | |
| 27 Jul 2026 | 6 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/openshift-container-platform-4.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Red Hat OpenShift Container Platform 4 vulnerabilities", https://junglewise.ai/threats/technologies/openshift-container-platform-4, 26 September 2026.