{"schema_version":1,"title":"Redhat vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 41 vulnerabilities in Redhat: 0 in the last 7 days and 9 in the last 90 days, 4 of them critical and 0 exploited in the wild. The most recent, CVE-2026-78475, was published on 24 August 2026. 13 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/redhat","json_url":"https://junglewise.ai/threats/vendors/redhat.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/redhat","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":13,"all_time":41,"critical":4,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":9,"last_365_days":29},"latest":[{"cve":"CVE-2026-78475","cvss":6.1,"epss":0.0026,"slug":"cve-2026-78475-gimp-file-pix-plugin-stack-overflow-in-pix-image-processing","title":"GIMP file-pix plugin stack overflow in PIX image processing","severity":"medium","exploited":false,"published_at":"2026-08-24T18:17:34.807+00:00","url":"https://junglewise.ai/threats/cve-2026-78475-gimp-file-pix-plugin-stack-overflow-in-pix-image-processing"},{"cve":"CVE-2026-74247","cvss":4.2,"epss":0.0025,"slug":"cve-2026-74247-red-hat-quay-server-side-request-forgery-in-build-api","title":"Red Hat Quay Server-Side Request Forgery in build API","severity":"medium","exploited":false,"published_at":"2026-08-14T23:16:34.73+00:00","url":"https://junglewise.ai/threats/cve-2026-74247-red-hat-quay-server-side-request-forgery-in-build-api"},{"cve":"CVE-2026-74245","cvss":5.9,"epss":0.0042,"slug":"cve-2026-74245-red-hat-quay-authentication-bypass-in-exported-logs","title":"Red Hat Quay authentication bypass in exported logs","severity":"medium","exploited":false,"published_at":"2026-08-14T23:16:34.6+00:00","url":"https://junglewise.ai/threats/cve-2026-74245-red-hat-quay-authentication-bypass-in-exported-logs"},{"cve":"CVE-2026-74244","cvss":5.9,"epss":0.0023,"slug":"cve-2026-74244-red-hat-quay-stripe-webhook-signature-validation-bypass","title":"Red Hat Quay Stripe webhook signature validation bypass","severity":"medium","exploited":false,"published_at":"2026-08-14T23:16:34.49+00:00","url":"https://junglewise.ai/threats/cve-2026-74244-red-hat-quay-stripe-webhook-signature-validation-bypass"},{"cve":"CVE-2026-74243","cvss":6.5,"epss":0.0046,"slug":"cve-2026-74243-red-hat-quay-authentication-bypass-in-security-scanner","title":"Red Hat Quay authentication bypass in security scanner notification endpoint","severity":"medium","exploited":false,"published_at":"2026-08-14T23:16:34.36+00:00","url":"https://junglewise.ai/threats/cve-2026-74243-red-hat-quay-authentication-bypass-in-security-scanner"},{"cve":"CVE-2026-74242","cvss":5.3,"epss":0.0033,"slug":"cve-2026-74242-red-hat-quay-notification-uuid-authorization-bypass","title":"Red Hat Quay notification UUID authorization bypass","severity":"medium","exploited":false,"published_at":"2026-08-14T23:16:34.227+00:00","url":"https://junglewise.ai/threats/cve-2026-74242-red-hat-quay-notification-uuid-authorization-bypass"},{"cve":"CVE-2026-74241","cvss":4.8,"epss":0.0031,"slug":"cve-2026-74241-red-hat-quay-ldap-injection-in-external-authentication","title":"Red Hat Quay LDAP injection in external authentication","severity":"medium","exploited":false,"published_at":"2026-08-14T23:16:34.093+00:00","url":"https://junglewise.ai/threats/cve-2026-74241-red-hat-quay-ldap-injection-in-external-authentication"},{"cve":"CVE-2026-74240","cvss":5.4,"epss":0.0029,"slug":"cve-2026-74240-red-hat-quay-jwt-validation-bypass-in-federated-authentication","title":"Red Hat Quay JWT validation bypass in federated authentication","severity":"medium","exploited":false,"published_at":"2026-08-14T23:16:33.96+00:00","url":"https://junglewise.ai/threats/cve-2026-74240-red-hat-quay-jwt-validation-bypass-in-federated-authentication"},{"cve":"CVE-2026-71846","cvss":6.5,"epss":0.0016,"slug":"cve-2026-71846-red-hat-insights-client-excessive-kubernetes-permissions-in","title":"Red Hat insights-client excessive Kubernetes permissions in ServiceAccount","severity":"medium","exploited":false,"published_at":"2026-08-12T22:17:16.143+00:00","url":"https://junglewise.ai/threats/cve-2026-71846-red-hat-insights-client-excessive-kubernetes-permissions-in"},{"cve":"CVE-2026-8863","cvss":0,"slug":"cve-2026-8863-multiple-vendors-uefi-shim-secure-boot-bypass-via-sbat-validation","title":"Multiple Vendors UEFI SHIM Secure Boot bypass via SBAT validation failure","severity":"info","exploited":false,"published_at":"2026-06-09T19:17:59.21+00:00","url":"https://junglewise.ai/threats/cve-2026-8863-multiple-vendors-uefi-shim-secure-boot-bypass-via-sbat-validation"},{"cve":"CVE-2026-6859","cvss":8.8,"epss":0.0077,"slug":"cve-2026-6859-instructlab-arbitrary-code-execution-via-hardcoded-trust-remote","title":"InstructLab arbitrary code execution via hardcoded trust_remote_code","severity":"high","exploited":false,"published_at":"2026-04-22T14:17:07.687+00:00","url":"https://junglewise.ai/threats/cve-2026-6859-instructlab-arbitrary-code-execution-via-hardcoded-trust-remote"},{"cve":"CVE-2026-6855","cvss":7.1,"epss":0.0022,"slug":"cve-2026-6855-red-hat-instructlab-path-traversal-in-chat-session-handler","title":"Red Hat InstructLab path traversal in chat session handler","severity":"high","exploited":false,"published_at":"2026-04-22T13:16:22.41+00:00","url":"https://junglewise.ai/threats/cve-2026-6855-red-hat-instructlab-path-traversal-in-chat-session-handler"},{"cve":"CVE-2026-6848","cvss":5.4,"epss":0.0007,"slug":"cve-2026-6848-red-hat-quay-authentication-bypass-in-sensitive-operations-re","title":"Red Hat Quay authentication bypass in sensitive operations re-verification","severity":"medium","exploited":false,"published_at":"2026-04-22T10:16:52.347+00:00","url":"https://junglewise.ai/threats/cve-2026-6848-red-hat-quay-authentication-bypass-in-sensitive-operations-re"},{"cve":"CVE-2026-1584","cvss":7.5,"epss":0.0133,"slug":"cve-2026-1584-gnutls-null-pointer-dereference-in-psk-binder-verification","title":"GnuTLS NULL pointer dereference in PSK binder verification","severity":"high","exploited":false,"published_at":"2026-04-09T18:16:44.047+00:00","url":"https://junglewise.ai/threats/cve-2026-1584-gnutls-null-pointer-dereference-in-psk-binder-verification"},{"cve":"CVE-2025-58713","cvss":6.4,"epss":0.0015,"slug":"cve-2025-58713-red-hat-process-automation-manager-privilege-escalation-in","title":"Red Hat Process Automation Manager privilege escalation in container images","severity":"medium","exploited":false,"published_at":"2026-04-08T14:16:26.433+00:00","url":"https://junglewise.ai/threats/cve-2025-58713-red-hat-process-automation-manager-privilege-escalation-in"},{"cve":"CVE-2025-57853","cvss":6.4,"epss":0.0016,"slug":"cve-2025-57853-red-hat-web-terminal-privilege-escalation-in-container-images","title":"Red Hat Web Terminal privilege escalation in container images","severity":"medium","exploited":false,"published_at":"2026-04-08T14:16:26.02+00:00","url":"https://junglewise.ai/threats/cve-2025-57853-red-hat-web-terminal-privilege-escalation-in-container-images"},{"cve":"CVE-2025-57851","cvss":6.4,"epss":0.0011,"slug":"cve-2025-57851-red-hat-multicluster-engine-for-kubernetes-privilege-escalation","title":"Red Hat Multicluster Engine for Kubernetes privilege escalation in /etc/passwd","severity":"medium","exploited":false,"published_at":"2026-04-08T14:16:25.817+00:00","url":"https://junglewise.ai/threats/cve-2025-57851-red-hat-multicluster-engine-for-kubernetes-privilege-escalation"},{"cve":"CVE-2025-57847","cvss":6.4,"epss":0.0015,"slug":"cve-2025-57847-red-hat-ansible-automation-platform-privilege-escalation-in","title":"Red Hat Ansible Automation Platform privilege escalation in container images","severity":"medium","exploited":false,"published_at":"2026-04-08T14:16:25.577+00:00","url":"https://junglewise.ai/threats/cve-2025-57847-red-hat-ansible-automation-platform-privilege-escalation-in"},{"cve":"CVE-2025-14821","cvss":7.8,"epss":0.0013,"slug":"cve-2025-14821-libssh-insecure-default-configuration-on-windows","title":"libssh insecure default configuration on Windows","severity":"high","exploited":false,"published_at":"2026-04-07T17:16:25.433+00:00","url":"https://junglewise.ai/threats/cve-2025-14821-libssh-insecure-default-configuration-on-windows"},{"cve":"CVE-2026-4740","cvss":8.2,"epss":0.0016,"slug":"cve-2026-4740-open-cluster-management-privilege-escalation-in-certificate","title":"Open Cluster Management privilege escalation in certificate renewal validation","severity":"high","exploited":false,"published_at":"2026-04-07T15:17:46.797+00:00","url":"https://junglewise.ai/threats/cve-2026-4740-open-cluster-management-privilege-escalation-in-certificate"},{"cve":"CVE-2026-3184","cvss":3.7,"epss":0.0044,"slug":"cve-2026-3184-util-linux-login-access-control-bypass-via-hostname","title":"util-linux login access control bypass via hostname canonicalization","severity":"low","exploited":false,"published_at":"2026-04-03T19:17:23.377+00:00","url":"https://junglewise.ai/threats/cve-2026-3184-util-linux-login-access-control-bypass-via-hostname"},{"cve":"CVE-2026-4948","cvss":5.5,"epss":0.0002,"slug":"cve-2026-4948-firewalld-incorrect-authorization-in-d-bus-setters","title":"firewalld incorrect authorization in D-Bus setters","severity":"medium","exploited":false,"published_at":"2026-03-27T06:16:39.543+00:00","url":"https://junglewise.ai/threats/cve-2026-4948-firewalld-incorrect-authorization-in-d-bus-setters"},{"cve":"CVE-2026-4874","cvss":3.1,"epss":0.0033,"slug":"cve-2026-4874-keycloak-ssrf-via-oidc-token-endpoint-manipulation","title":"Keycloak SSRF via OIDC token endpoint manipulation","severity":"low","exploited":false,"published_at":"2026-03-26T08:16:22.7+00:00","url":"https://junglewise.ai/threats/cve-2026-4874-keycloak-ssrf-via-oidc-token-endpoint-manipulation"},{"cve":"CVE-2026-4366","cvss":5.8,"epss":0.0004,"slug":"cve-2026-4366-keycloak-ssrf-via-improper-http-redirect-handling-in-keycloak","title":"Keycloak SSRF via improper HTTP redirect handling in keycloak-services","severity":"medium","exploited":false,"published_at":"2026-03-18T04:17:32.45+00:00","url":"https://junglewise.ai/threats/cve-2026-4366-keycloak-ssrf-via-improper-http-redirect-handling-in-keycloak"},{"cve":"CVE-2025-8766","cvss":6.4,"epss":0,"slug":"cve-2025-8766-red-hat-noobaa-core-privilege-escalation-via-incorrect-etc-passwd","title":"Red Hat NooBaa Core privilege escalation via incorrect /etc/passwd permissions","severity":"medium","exploited":false,"published_at":"2026-03-13T19:53:56.157+00:00","url":"https://junglewise.ai/threats/cve-2025-8766-red-hat-noobaa-core-privilege-escalation-via-incorrect-etc-passwd"}],"vendor":{"hub":true,"name":"Redhat","slug":"redhat","homepage":"https://www.redhat.com/","description":"Cisco Systems is a provider of networking, cloud, and cybersecurity solutions.","url":"https://junglewise.ai/threats/vendors/redhat"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":8},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-1999-1299","cvss":10,"slug":"cve-1999-1299-linux-rcp-arbitrary-file-overwrite-via-uid-65535-integer","title":"Linux rcp arbitrary file overwrite via UID 65535 integer signedness error","severity":"critical","exploited":false,"published_at":"1997-02-03T05:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-1299-linux-rcp-arbitrary-file-overwrite-via-uid-65535-integer"},{"cve":"CVE-2016-9636","cvss":9.8,"slug":"cve-2016-9636-gstreamer-heap-buffer-overflow-in-flic-decoder","title":"GStreamer heap buffer overflow in FLIC decoder","severity":"critical","exploited":false,"published_at":"2017-01-27T22:59:02.053+00:00","url":"https://junglewise.ai/threats/cve-2016-9636-gstreamer-heap-buffer-overflow-in-flic-decoder"},{"cve":"CVE-2016-9635","cvss":9.8,"slug":"cve-2016-9635-gstreamer-heap-buffer-overflow-in-flic-decoder","title":"GStreamer heap buffer overflow in FLIC decoder","severity":"critical","exploited":false,"published_at":"2017-01-27T22:59:01.99+00:00","url":"https://junglewise.ai/threats/cve-2016-9635-gstreamer-heap-buffer-overflow-in-flic-decoder"},{"cve":"CVE-2016-9634","cvss":9.8,"slug":"cve-2016-9634-gstreamer-heap-buffer-overflow-in-flic-decoder","title":"GStreamer heap buffer overflow in FLIC decoder","severity":"critical","exploited":false,"published_at":"2017-01-27T22:59:01.943+00:00","url":"https://junglewise.ai/threats/cve-2016-9634-gstreamer-heap-buffer-overflow-in-flic-decoder"},{"cve":"CVE-2026-6859","cvss":8.8,"epss":0.0077,"slug":"cve-2026-6859-instructlab-arbitrary-code-execution-via-hardcoded-trust-remote","title":"InstructLab arbitrary code execution via hardcoded trust_remote_code","severity":"high","exploited":false,"published_at":"2026-04-22T14:17:07.687+00:00","url":"https://junglewise.ai/threats/cve-2026-6859-instructlab-arbitrary-code-execution-via-hardcoded-trust-remote"},{"cve":"CVE-2026-4740","cvss":8.2,"epss":0.0016,"slug":"cve-2026-4740-open-cluster-management-privilege-escalation-in-certificate","title":"Open Cluster Management privilege escalation in certificate renewal validation","severity":"high","exploited":false,"published_at":"2026-04-07T15:17:46.797+00:00","url":"https://junglewise.ai/threats/cve-2026-4740-open-cluster-management-privilege-escalation-in-certificate"},{"cve":"CVE-2026-3009","cvss":8.1,"epss":0.0047,"slug":"cve-2026-3009-keycloak-authentication-bypass-via-disabled-identity-provider","title":"Keycloak authentication bypass via disabled Identity Provider","severity":"high","exploited":false,"published_at":"2026-03-05T19:16:18.193+00:00","url":"https://junglewise.ai/threats/cve-2026-3009-keycloak-authentication-bypass-via-disabled-identity-provider"},{"cve":"CVE-2025-14821","cvss":7.8,"epss":0.0013,"slug":"cve-2025-14821-libssh-insecure-default-configuration-on-windows","title":"libssh insecure default configuration on Windows","severity":"high","exploited":false,"published_at":"2026-04-07T17:16:25.433+00:00","url":"https://junglewise.ai/threats/cve-2025-14821-libssh-insecure-default-configuration-on-windows"},{"cve":"CVE-2026-1584","cvss":7.5,"epss":0.0133,"slug":"cve-2026-1584-gnutls-null-pointer-dereference-in-psk-binder-verification","title":"GnuTLS NULL pointer dereference in PSK binder verification","severity":"high","exploited":false,"published_at":"2026-04-09T18:16:44.047+00:00","url":"https://junglewise.ai/threats/cve-2026-1584-gnutls-null-pointer-dereference-in-psk-binder-verification"},{"cve":"CVE-1999-0037","cvss":7.5,"slug":"cve-1999-0037-bellcore-metamail-arbitrary-command-execution-via-message-headers","title":"Bellcore metamail arbitrary command execution via message headers","severity":"high","exploited":false,"published_at":"1997-05-21T04:00:00+00:00","url":"https://junglewise.ai/threats/cve-1999-0037-bellcore-metamail-arbitrary-command-execution-via-message-headers"}],"generated_at":"2026-09-26T15:07:00.181821+00:00","technologies":[{"name":"Redhat Linux","slug":"linux","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/linux"},{"name":"Redhat 389 Directory Server","slug":"389-directory-server","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/389-directory-server"},{"name":"Redhat Quay","slug":"quay","vulnerabilities":8,"url":"https://junglewise.ai/threats/technologies/quay"},{"name":"Redhat Enterprise Linux","slug":"enterprise-linux","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/enterprise-linux"},{"name":"Redhat Advanced Cluster Management For Kubernetes","slug":"advanced-cluster-management-for-kubernetes","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/advanced-cluster-management-for-kubernetes"},{"name":"Redhat Enterprise Linux Desktop","slug":"enterprise-linux-desktop","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-desktop"},{"name":"Redhat Enterprise Linux Hpc Node","slug":"enterprise-linux-hpc-node","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-hpc-node"},{"name":"Redhat Enterprise Linux Server","slug":"enterprise-linux-server","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-server"},{"name":"Redhat Enterprise Linux Workstation","slug":"enterprise-linux-workstation","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/enterprise-linux-workstation"},{"name":"Redhat Hardened Images","slug":"hardened-images","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/hardened-images"},{"name":"Redhat Jboss Enterprise Application Platform","slug":"jboss-enterprise-application-platform","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/jboss-enterprise-application-platform"},{"name":"Redhat Jboss Enterprise Application Platform Expansion Pack","slug":"jboss-enterprise-application-platform-expansion-pack","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/jboss-enterprise-application-platform-expansion-pack"},{"name":"Redhat Single Sign-On","slug":"single-sign-on","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/single-sign-on"}]}