Vendor
Red Hat vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 702 vulnerabilities in Red Hat: 42 in the last 7 days and 257 in the last 90 days, 77 of them critical and 6 exploited in the wild. The most recent, CVE-2026-96448, was published on 25 September 2026. 58 technologies have a page of their own.
- Last 7 days
- 42
- Last 90 days
- 257
- Critical, all time
- 77
- Exploited in the wild
- 6
About Red Hat
A provider of open-source software solutions, including the Red Hat Enterprise Linux operating system.
Red Hat technologies
- Red Hat Enterprise Linux 9146
- Red Hat Enterprise Linux 10140
- Red Hat Enterprise Linux 8132
- Red Hat Enterprise Linux 767
- Red Hat Enterprise Linux 655
- Red Hat Build of Keycloak54
- Red Hat Keycloak48
- Red Hat Enterprise Linux AppStream46
- Red Hat OpenShift Container Platform 436
- Red Hat Developer Hub28
- Red Hat Multicluster Global Hub19
- Red Hat AI Inference Server16
- Red Hat Enterprise Linux 9.014
- Red Hat Self-service automation portal14
- Red Hat OpenShift AI13
- Red Hat Quay12
- Red Hat Self-Service Automation Portal 212
- Red Hat Advanced Cluster Security for Kubernetes11
- Red Hat Enterprise Linux AI11
- Red Hat Ansible Automation Platform10
- Red Hat Enterprise Linux 10.010
- Red Hat Enterprise Linux 8.010
- Red Hat Trusted Artifact Signer9
- Red Hat streams for Apache Kafka8
- Red Hat OpenShift Lightspeed7
- Red Hat WildFly7
- Red Hat 389-Ds-Base6
- Red Hat Lightspeed Core6
- Red Hat build of Apache Camel for Spring Boot6
- Red Hat Build of Apache Camel for Quarkus5
- Red Hat Enterprise Linux 7.05
- Red Hat Enterprise-Linux-Appstream-Eus5
- Red Hat Enterprise Linux5
- Red Hat ABRT4
- Red Hat AMQ Broker4
- Red Hat Apicurio-Registry4
- Red Hat Data Grid 84
- Red Hat Gfs2-Utils4
- Red Hat Gstreamer-Plugins-Good4
- Red Hat Hawtio-Operator4
- Red Hat In-Vehicle Operating System 14
- Red Hat Katello4
- Red Hat Build of Podman Desktop4
- Red Hat Single Sign-On 74
- Red Hat Ansible Lightspeed extension for Visual Studio Code3
- Red Hat build of Debezium3
- Red Hat Podman Desktop3
- Red Hat Certificate System3
- Red Hat Connectivity Link3
- Red Hat Cost Management Metrics Operator3
- Red Hat Enterprise Application Platform3
- Red Hat Fuse 73
- Red Hat Gstreamer-Plugins-Bad-Free3
- Red Hat OpenShift Container Platform 4.03
- Red Hat PipeWire3
- Red Hat Red-Hat-Enterprise-Linux-Server3
- Red Hat RESTEasy3
- Red Hat WildFly Core3
Latest Red Hat vulnerabilities
- CVE-2026-96448: Keycloak privilege escalation in Fine-Grained Admin PermissionsmediumCVSS 6.6EPSS 0.2%
- CVE-2026-97846: Keycloak mTLS holder-of-key binding bypass in Standard Token ExchangemediumCVSS 6.8EPSS 0.1%
- CVE-2026-95519: rpm arbitrary code execution via manifest macro expansionhighCVSS 7.8EPSS 0.1%
- CVE-2026-94416: Red Hat Ansible Automation Platform authorization bypass in gatewaymediumCVSS 6.8EPSS 0.4%
- CVE-2026-97311: Keycloak Admin REST API authorization bypass in group retrievalmediumCVSS 4.3EPSS 0.3%
- CVE-2026-97177: Keycloak Admin REST API authorization bypass in user updatemediumCVSS 6.6EPSS 0.2%
- CVE-2026-97176: Keycloak authentication level enforcement bypassmediumCVSS 4.2EPSS 0.2%
- CVE-2026-75887: Red Hat OpenShift console path traversal in locale handlerhighCVSS 7.5EPSS 0.4%
- CVE-2026-75886: Red Hat OpenShift Console unauthenticated proxy relay in CatalogdHandlerhighCVSS 7.2EPSS 0.3%
- CVE-2026-85475: Red Hat Ansible Automation Platform controller command injection in rsyslog configurationhighCVSS 7.2EPSS 0.4%
- CVE-2026-84724: Red Hat Ansible Automation Platform argument injection in system-job subsystemmediumCVSS 6.6EPSS 0.3%
- CVE-2026-84721: Red Hat Ansible Automation Platform server-side request forgery in email backendmediumCVSS 6.4EPSS 0.2%
- CVE-2026-84720: Red Hat Ansible Automation Platform controller information disclosure via database column filteringmediumCVSS 6.5EPSS 0.3%
- CVE-2026-84719: Red Hat Ansible Automation Platform controller privilege escalation in WorkflowJobTemplate copycriticalCVSS 9.9EPSS 0.4%
- CVE-2026-84718: Red Hat Ansible Automation Platform Controller X-Forwarded-For header spoofingmediumCVSS 4.3EPSS 0.1%
- CVE-2026-84717: Red Hat Ansible Automation Platform automation-controller webhook signature verification bypassmediumCVSS 5.3EPSS 0.3%
- CVE-2026-84716: Ansible automation-controller certificate signing vulnerability in install-bundlemediumCVSS 6.6EPSS 0.2%
- CVE-2026-84714: Red Hat Ansible Automation Platform Jinja injection in input validationhighCVSS 7.1EPSS 0.3%
- CVE-2026-84713: Red Hat Ansible Automation Platform Controller information disclosure in notification subsystemmediumCVSS 6.5EPSS 0.3%
- CVE-2026-84712: Red Hat Ansible Automation Controller API information disclosuremediumCVSS 5.3EPSS 0.3%
- CVE-2026-84706: Red Hat Ansible Automation Platform automation-controller credential type injectionhighCVSS 7.6EPSS 0.3%
- CVE-2026-84691: Red Hat Ansible Automation Platform controller format string in API error logginghighCVSS 8.7EPSS 0.2%
- CVE-2026-84683: Red Hat Ansible Automation Platform controller XSS via ANSI escape sequenceshighCVSS 8.7EPSS 0.3%
- CVE-2026-75884: Red Hat AWX incomplete blocklist in container group pod_spec_overridecriticalCVSS 9.1EPSS 0.4%
- CVE-2026-84502: Red Hat Ansible Automation Platform controller command injection in project scm_urlcriticalCVSS 9.9EPSS 0.6%
Most severe Red Hat vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2017-12149: Red Hat JBoss Application Server Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2010-1871: Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerabilitycriticalexploited in the wildCVSS 8.8
- CVE-2023-4911: GNU C Library Buffer Overflow Vulnerabilitycriticalexploited in the wildCVSS 7.8
- CVE-2015-5287: Red Hat ABRT privilege escalation via symlink attackcriticalexploited in the wildCVSS 7EPSS 5.0%
- CVE-2026-53362: Linux Kernel buffer overflow in IPv6 paged allocationcriticalexploited in the wildCVSS 6.2EPSS 0.7%
- CVE-2015-3246: Red Hat Libuser race condition in passwd file handlingcriticalexploited in the wildEPSS 8.8%
- CVE-2026-34078: Flatpak sandbox escape via symlink following in sandbox-exposecriticalCVSS 10EPSS 1.6%
- CVE-2025-14009: NLTK Zip Slip remote code execution in downloader componentcriticalCVSS 10EPSS 0.9%
- CVE-2026-44005: patriksimek vm2 sandbox escape via host prototype mutationcriticalCVSS 10EPSS 0.8%
- CVE-2026-44006: patriksimek vm2 sandbox escape via arbitrary prototype accesscriticalCVSS 10EPSS 0.8%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 28 | 2 | |
| 6 Jul 2026 | 13 | 0 | |
| 13 Jul 2026 | 21 | 0 | |
| 20 Jul 2026 | 40 | 1 | |
| 27 Jul 2026 | 39 | 0 | |
| 3 Aug 2026 | 2 | 0 | |
| 10 Aug 2026 | 20 | 1 | |
| 17 Aug 2026 | 4 | 2 | |
| 24 Aug 2026 | 8 | 2 | |
| 31 Aug 2026 | 7 | 0 | |
| 7 Sep 2026 | 9 | 1 | |
| 14 Sep 2026 | 24 | 1 | |
| 21 Sep 2026 | 42 | 4 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/red-hat.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Red Hat vulnerabilities", https://junglewise.ai/threats/vendors/red-hat, 26 September 2026.