Red hat enterprise linux
This hub aggregates every CVE we track for Red hat enterprise linux, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
10,968
CVEs tracked
906
Critical
4,278
High
113
In CISA KEV
Severity distribution
MEDIUM5,289HIGH4,278CRITICAL906LOW495
Monthly trend
184
128
183
107
288
149
127
254
259
282
69
377
346
75
199
107
45
118
88
58
98
93
100
92
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Red hat enterprise linux.
- CVE-2026-91202Cockpit-files: cockpit-files: arbitrary file ownership change via symlink following in privileged paste6.1
- CVE-2026-91203Cockpit-files: cockpit-files: arbitrary file ownership and permission modification via symlink race condition6.0
- CVE-2026-91205Cockpit-files: cockpit-files: local attacker can hijack file ownership via symlink race6.0
- CVE-2026-92768Cockpit-machines: cockpit-machines: sensitive data exposure via command-line arguments5.5
- CVE-2026-92747Cockpit-machines: cockpit-machines: sensitive data exposure of guest credentials via json argument in process list5.0
- CVE-2026-92745Cockpit-machines: cockpit-machines: information disclosure of rhsm offline token via process arguments5.0
- CVE-2026-91142Cockpit: integer overflow in `do_lastlog()` offset calculation can misaddress `lastlog` entries on ilp32 builds3.6
- CVE-2026-91147Cockpit: cockpit: denial of service in `cockpit-ws` due to url-root handling without a trailing slash5.9
- CVE-2026-91149Cockpit: cockpit: denial of service via unbounded connection thread spawning7.5
- CVE-2026-93676Xdg-dbus-proxy: xdg-dbus-proxy: filtering for broadcast messages bypasses path/interface/member checks3.2
- CVE-2026-93653Poppler: poppler: unbounded cpu loop in splashoutputdev::tilingpatternfill via unvalidated tiling-pattern repeat count (denial of service)5.5
- CVE-2026-81627Qemu-kvm: vapic writable rom alias can escape the option-rom window and expose locked smram6.7
- CVE-2026-89058Resteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wildcard config7.4
- CVE-2026-89059Resteasy-core: resteasy: iioimageprovider unbounded image decode (decompression-bomb dos)7.5
- CVE-2026-76781Libxml2: libxml2: null pointer dereference parsing nextcatalog without catalog attribute5.5
Product normalization is registry-driven with AI assist and human review. How it works