Red hat jboss enterprise application platform 7.4 els on rhel 8
This hub aggregates every CVE we track for Red hat jboss enterprise application platform 7.4 els on rhel 8, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
15
CVEs tracked
2
Critical
13
High
0
In CISA KEV
Severity distribution
HIGH13CRITICAL2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
1
0
0
1
2
0
0
0
0
0
0
10
1
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Red hat jboss enterprise application platform 7.4 els on rhel 8.
- CVE-2026-86404Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging-activemq-subsystem: artemis messaging handlers in red hat eap permit deserialization by default8.8
- CVE-2026-15567Wildfly: wildfly-iiop: wildfly-jacorb: wildfly: pre-auth denial of service on the iiop listener7.5
- CVE-2026-15565Undertow: undertow-websockets: undertow: pre-auth dos on websocket endpoint with @serverendpoint class with any @onmessage method7.5
- CVE-2026-15563Wildfly-iiop-openjdk: missing authentication on eap's iiop nameservice leads to mitm or dos7.4
- CVE-2026-15562Jboss-remoting: jboss-remoting: integer overflow in messagereader leads to pre-authentication denial of service7.5
- CVE-2026-15561Undertow-core: oom via missing limits in chunked trailer in eap's undertow7.5
- CVE-2026-15560Openjdk-orb: unauthed class loading via iiop in eap8.1
- CVE-2026-15556Picketlink-federation: picketlink saml 2.0 auth bypass via missing assertions8.1
- CVE-2026-15554Undertow-core: undertow: authentication bypass via ajp ssl_cert/is_ssl forgery7.4
- CVE-2026-15555Jboss-marshalling-river: wildfly-clustering-infinispan-marshalling: jboss deserialization rce via unfiltered river unmarshaller8.8
- CVE-2026-10579Picketlink-federation: auth bypass in picketlink saml unsolicited-response9.8
- CVE-2026-0603Org.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injection8.3
- CVE-2025-12543Undertow-core: undertow http server fails to reject malformed host headers leading to potential cache poisoning and ssrf9.6
- CVE-2024-3884Undertow: outofmemory when parsing form data encoding with application/x-www-form-urlencoded7.5
- CVE-2025-9784Undertow: undertow madeyoureset http/2 ddos vulnerability7.5
Product normalization is registry-driven with AI assist and human review. How it works