CVE-2026-105306Keycloak-services: keycloak-services: token introspection audience bypass via dynamic client registration Exploitation status Not confirmed Fix Not confirmed Affected product R Red Hat Build of Keycloak Published 10/05/2026 Severity Medium CVE-2026-105302Keycloak-services: keycloak-services: user session note mapper exposes upstream idp access tokens Exploitation status Not confirmed Fix Not confirmed Affected product R Red Hat Build of Keycloak Published 10/05/2026 Severity Medium CVE-2026-105301Keycloak-services: keycloak-services: blind ssrf via x.509 authenticator fetching attacker-controlled crl-dp/ocsp urls Exploitation status Not confirmed Fix Not confirmed Affected product R Red Hat Build of Keycloak Published 10/05/2026 Severity Medium CVE-2026-104988Pki-core: dogtag-pki: redhat-pki: pki: est fullcmc authentication bypass allows certificate mis-issuance with arbitrary subject Exploitation status Not confirmed Fix Not confirmed Affected product R Red Hat Certificate System 10 Published 10/02/2026 Severity High CVE-2026-94422xdg-dbus-proxy: message filtering bypass via reply serial allows sandbox escape Exploitation status Not known exploited Fix YesAffected product R Red Hat Enterprise Linux 9 Published 10/02/2026 Severity High CVE-2026-95512Freetype: freetype: denial of service via repeated subroutine allocations in cid font loader Exploitation status Not confirmed Fix Not confirmed Affected product R Red Hat Hardened Images Published 10/02/2026 Severity Medium CVE-2026-86345389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result Exploitation status Not confirmed Fix Not confirmed Affected product R Red Hat Directory Server 11 Published 10/01/2026 Severity Critical CVE-2026-86344389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Directory Server 11 Published 10/01/2026 Severity High CVE-2026-103884Keycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file read Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Build of Keycloak Published 10/01/2026 Severity Medium CVE-2026-56098Rubygem-katello: improper authorization logic allows resource enumeration Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Satellite 6.16 for RHEL 8 Published 10/01/2026 Severity Medium CVE-2026-56097Rubygem-katello: sql injection in registry proxy via labels Exploitation status Not confirmed Fix Not confirmed Affected product R Red Hat Satellite 6.16 for RHEL 8 Published 10/01/2026 Severity Medium CVE-2026-12542Foreman: command injection in foreman-tail Exploitation status Not confirmed Fix Not confirmed Affected product R Red Hat Satellite 6.16 for RHEL 8 Published 10/01/2026 Severity Medium CVE-2026-12545Rubygem-hammer_cli: command injection via insecure editor invocation Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Satellite 6.16 for RHEL 8 Published 10/01/2026 Severity Medium CVE-2026-96658Foreman: safemode bypass leading to rce Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Satellite 6.16 for RHEL 8 Published 10/01/2026 Severity Critical CVE-2026-96659Foreman: excessive permissions for viewer role on preview Exploitation status Not confirmed Fix Not confirmed Affected product R Red Hat Satellite 6.16 for RHEL 8 Published 10/01/2026 Severity Critical CVE-2026-12544Foreman: ssti and insecure deserialization in foreman-rake configuration Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Satellite 6.16 for RHEL 8 Published 10/01/2026 Severity High CVE-2026-12541Foreman: command injection in foreman-rake database tasks Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Satellite 6.16 for RHEL 8 Published 10/01/2026 Severity High CVE-2026-12540Foreman: command injection in foreman-rake errors:fetch_log via request_id parameter Exploitation status Not confirmed Fix Not confirmed Affected product R Red Hat Satellite 6.16 for RHEL 8 Published 10/01/2026 Severity High CVE-2026-12423Foreman: unauthenticated information disclosure via provisioning token validation flaw Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Satellite 6.16 for RHEL 8 Published 10/01/2026 Severity High CVE-2026-12405Rubygem-foreman_remote_execution: command injection in job invocations via effective_user parameter Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Satellite 6.16 for RHEL 8 Published 10/01/2026 Severity High CVE-2026-103754Ansible-runner: ansible-runner: path traversal and symlink escape in unstream_dir() allows file write outside the target directory Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2 Published 10/01/2026 Severity Medium CVE-2026-96577Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without authentication, with delete enabled Exploitation status Not confirmed Fix Not confirmed Affected product R Red Hat OpenShift Container Platform 4 Published 10/01/2026 Severity High CVE-2026-83589Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat OpenShift Container Platform 4 Published 10/01/2026 Severity Medium CVE-2026-103641Gegl: gegl04: gegl: out-of-bounds read in the radiance hdr uncompressed scanline decoder Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 10/01/2026 Severity Medium CVE-2026-103399Libsoup: soupserver: http/1 request smuggling via undrained expect: 100-continue body Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/30/2026 Severity Medium CVE-2026-101295Oc-mirror: oc-mirror: path traversal / arbitrary file write in operator catalog image extraction Exploitation status Not known exploited Fix Not confirmed Affected product Not confirmed Published 09/30/2026 Severity High CVE-2026-103242Rpm: heap-based buffer overflow write in hex2binv() via a mistyped rpmtag_filesignatures header tag Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/30/2026 Severity High CVE-2026-62146Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socket Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat OpenShift Container Platform 4 Published 09/30/2026 Severity High CVE-2026-102560Libsoup: libsoup: heap buffer overflow during outgoing permessage-deflate buffer growth Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/29/2026 Severity High CVE-2026-102559Libsoup: libsoup: heap buffer overflow during websocket client-frame masking Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/29/2026 Severity High CVE-2026-102558Libsoup: libsoup: heap buffer overflow during websocket receive-buffer growth Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/29/2026 Severity High CVE-2026-102555Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri base64 decoding Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/29/2026 Severity High CVE-2026-102623Kubevirt: kubevirt: virt-controller nil-pointer dereference via malformed ephemeral volume Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat OpenShift Virtualization 4 Published 09/29/2026 Severity Medium CVE-2026-102557Libsoup: libsoup: heap buffer overflow during websocket message reassembly Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/29/2026 Severity High CVE-2026-102556Libsoup: libsoup: heap buffer overflow from websocket pong signal type confusion Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/29/2026 Severity High CVE-2026-95520Rpm: rpm: integer overflow in iterreadarchivenext() leads to heap-based buffer overflow when parsing untrusted rpm packages Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/29/2026 Severity High CVE-2026-102474Dash: dash: heap out-of-bounds write in conv_escape via undersized unicode escape reservation Exploitation status Not known exploited Fix Not confirmed Affected product Not confirmed Published 09/29/2026 Severity Medium CVE-2026-102473Dash: dash: super-polynomial backtracking in pmatch when libc fnmatch is disabled Exploitation status Not known exploited Fix Not confirmed Affected product Not confirmed Published 09/29/2026 Severity Medium CVE-2026-97029Flatpak: flatpak: sandboxed app can signal unsandboxed processes in the same process group Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/29/2026 Severity Medium CVE-2026-97024Flatpak: flatpak: arbitrary write in root context via path traversal in deploy directory files/etc Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/29/2026 Severity High CVE-2026-97027Flatpak: flatpak: denial of service via unsanitized keys in exported desktop entry / d-bus service files Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/28/2026 Severity Low CVE-2026-97026Flatpak: flatpak: world-writable temporary child repositories in system-helper cache path Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/28/2026 Severity Low CVE-2026-97025Flatpak: flatpak: world-readable oci authentication token in system-helper cache path Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/28/2026 Severity Low CVE-2026-102010Gcc-toolset-15-gcc: gcc: gcc-toolset-16: gcc: denial of service via use-after-free in binary heap erase_if Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Hardened Images Published 09/28/2026 Severity High CVE-2026-97023Flatpak: flatpak: arbitrary file deletion in root context via path traversal in deploy directory export/bin Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/28/2026 Severity High CVE-2026-96740Streamshub/console: console-operator: streams for apache kafka console: unfiltered kafka client properties → sa-token exfiltration via config.providers Exploitation status Not known exploited Fix YesAffected product S StreamsHub Console for Apache Kafka® Published 09/28/2026 Severity Medium CVE-2026-87114Kube-compare: container:// reference extraction runs the image entrypoint and silently escalates to sudo Exploitation status Not known exploited Fix Not confirmed Affected product P Pen Drive Powered by Red Hat Lightspeed Published 09/28/2026 Severity High CVE-2026-101333Keycloak-services: keycloak-services: unbounded metric series creation via idp tag on broker login endpoint Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Build of Keycloak Published 09/28/2026 Severity Low CVE-2026-101292Artemis-core-client: unsafe reflection in apache activemq artemis federation message deserialization Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat JBoss Enterprise Application Platform 7.4.25 Published 09/28/2026 Severity High CVE-2026-86330Noobaa-core: noobaa-core: os command injection in cluster_internal_api.set_hostname_internal Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Openshift Data Foundation 4 Published 09/28/2026 Severity High CVE-2026-96284Flatpak: flatpak: arbitrary read-access to files in the system-helper context via oci symlink following Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/27/2026 Severity Low CVE-2026-96282Flatpak: flatpak: extension metadata path traversal file existence oracle Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/27/2026 Severity Low CVE-2026-96283Flatpak: flatpak: flatpak-system-helper cross-user cancelpull orphans another user's ongoing pull Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/27/2026 Severity Low CVE-2026-96281Flatpak: flatpak: unprivileged active user can bypass anti-downgrade checks for system apps/runtimes Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/27/2026 Severity Medium CVE-2026-96280Flatpak: flatpak: buffer overflow in oci delta stream path names on 32-bit systems Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/27/2026 Severity High CVE-2026-96279Flatpak: flatpak: path traversal issue in oci archive extraction via hardlinks Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/27/2026 Severity Medium CVE-2026-93834Qemu-kvm: 9pfs: use-after-free race in tlcreate/twalk allows vm guest escape Exploitation status Public exploit Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/25/2026 Severity High CVE-2026-96448Keycloak-services: keycloak-services: fgap v2 composite-blind role mapping allows privilege escalation Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Build of Keycloak Published 09/25/2026 Severity Medium CVE-2026-97846Keycloak-services: keycloak-services: standard token exchange v2 bypasses mtls holder-of-key binding Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Build of Keycloak Published 09/25/2026 Severity Medium CVE-2026-90959Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enables arbitrary file read and pulp container registry signing key theft Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2 Published 09/24/2026 Severity High CVE-2026-95521Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when installing a source rpm Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/24/2026 Severity High CVE-2026-95519Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify manifest flows) Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/24/2026 Severity High CVE-2026-94416Aap-gateway: aap-gateway: authorization bypass via workload identity token forgery Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2 Published 09/24/2026 Severity Medium CVE-2026-97311Keycloak-services: keycloak-services: admin rest api role-groups endpoint discloses groups without authorization Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Build of Keycloak Published 09/24/2026 Severity Medium CVE-2026-97185Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/24/2026 Severity High CVE-2026-97177Keycloak-services: keycloak-services: generic user update bypasses denied reset-password permission Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Build of Keycloak Published 09/24/2026 Severity Medium CVE-2026-97176Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cookie authenticator Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Build of Keycloak Published 09/24/2026 Severity Medium CVE-2026-75887Openshift/console: openshift/console: unauthenticated path traversal in i18n locale handler Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat OpenShift Container Platform 4.12 Published 09/23/2026 Severity High CVE-2026-75886Openshift/console: openshift/console: unauthenticated reverse proxy to in-cluster catalogd service with session token forwarding Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat OpenShift Container Platform 4.17 Published 09/23/2026 Severity High CVE-2026-84724Automation-controller: automation-controller: systemjob extra_vars.days argument injection into uncontainerized control-plane awx-manage process Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.5 for RHEL 8 Published 09/23/2026 Severity Medium CVE-2026-84721Automation-controller: automation-controller: email notification backend allows ssrf via user-controlled smtp host/port (internal port-scan oracle, smtp password exfil) Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.7 Published 09/23/2026 Severity Medium CVE-2026-84720Automation-controller: automation-controller: workflowjobnode.ancestor_artifacts lacks prevent_search, exposing no_log set_stats artifacts via orm-traversal count-oracle Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.5 for RHEL 8 Published 09/23/2026 Severity Medium CVE-2026-84718Automation-controller: automation-controller: client ip spoofing in audit/access logs via unrestricted x-forwarded-for trust Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.5 for RHEL 8 Published 09/23/2026 Severity Medium CVE-2026-84717Automation-controller: automation-controller: unauthenticated 200-vs-403 oracle in bitbucket data center webhook receiver enumerates webhook-enabled job templates Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.5 for RHEL 8 Published 09/23/2026 Severity Medium CVE-2026-84716Automation-controller: automation-controller: instance install_bundle issues 10-year, non-revocable receptor mesh-ca certificates for caller-chosen (and case-variant impersonating) hostnames Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.5 for RHEL 8 Published 09/23/2026 Severity Medium CVE-2026-84713Automation-controller: automation-controller: notification.recipients/subject/error lack prevent_search, allowing zero-privilege cross-tenant recovery of notification recipient secrets via filter oracle Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.7 Published 09/23/2026 Severity Medium CVE-2026-84712Automation-controller: automation-controller: unauthenticated /api/v2/ping/ discloses automation-mesh instance topology and instance-group membership Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.5 for RHEL 8 Published 09/23/2026 Severity Medium CVE-2026-96889Librsvg: use-after-free when xml includes have duplicated entities Exploitation status Public exploit Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/23/2026 Severity High CVE-2026-85475Automation-controller: automation-controller-container: automation-controller: rsyslog configuration injection via log_aggregator_* settings leads to remote code execution in the control-plane rsyslog component Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.7 Published 09/23/2026 Severity High CVE-2026-84719Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitizer omits instance_groups authorization (instancegroup use_role bypass to control-plane) Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.4 for RHEL 8 Published 09/23/2026 Severity Critical CVE-2026-84714Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jinja template injection into ad-hoc module_args, machine-credential fields, and host names, reaching ansible-core templating in the execution environment Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.5 for RHEL 8 Published 09/23/2026 Severity High CVE-2026-84706Automation-controller: automation-controller-container: automation-controller: credential type env-injector deny-list omits process-hijacking variables (bash_env/ld_preload) allowing code execution in the execution environment Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.5 for RHEL 8 Published 09/23/2026 Severity High CVE-2026-75884Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in container groups Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.4 for RHEL 8 Published 09/23/2026 Severity Critical CVE-2026-84691Automation-controller: automation-controller-container: automation-controller: format string injection in the api 4xx error log setting discloses django secret_key and database credentials to an administrator Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.5 for RHEL 8 Published 09/23/2026 Severity High CVE-2026-84683Automation-controller: automation-controller-container: automation-controller: stored cross-site scripting in the job stdout html view via ansi osc 8 hyperlink sequences (javascript: anchor) enabling session takeover Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.5 for RHEL 8 Published 09/23/2026 Severity High CVE-2026-84499Automation-controller: automation-controller-container: automation-controller: write-only survey password recovered in plaintext via schedule/workflowjobtemplatenode survey min/max validation error message Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.5 for RHEL 8 Published 09/23/2026 Severity High CVE-2026-84502Automation-controller: automation-controller-container: automation-controller: project scm_url argument injection into `git ls-remote --upload-pack` yields rce on the controller-task control-plane pod Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.4 for RHEL 8 Published 09/23/2026 Severity Critical CVE-2026-84474Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and x-forwarded-for spoofing of provisioning-callback host match Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.4 for RHEL 8 Published 09/23/2026 Severity Critical CVE-2026-84486Automation-controller: automation-controller-container: automation-controller: unauthenticated debug scheduler-trigger endpoints (allowany, routed without debug guard) allow advisory-lock starvation of job dispatch (dos) Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.6 for RHEL 9 Published 09/23/2026 Severity High CVE-2026-96546Gimp: gimp: one-byte out-of-bounds heap read in the uncompressed dds loader Exploitation status Public exploit Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/23/2026 Severity Low CVE-2026-71465Automation-controller: automation-controller-container: automation-controller: ad-hoc command limit field allows cli argument injection into ansible executable Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.5 for RHEL 8 Published 09/23/2026 Severity Low CVE-2026-71464Automation-controller: automation-controller-container: automation-controller: schedule and workflowjobtemplatenode scm_branch prompt bypasses leading-dash git-argument guard Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.5 for RHEL 8 Published 09/23/2026 Severity Low CVE-2026-71463Automation-controller: automation-controller-container: automation-controller: notification template jinja whitelist bypass via conditional gating leaks tracebacks Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.5 for RHEL 8 Published 09/23/2026 Severity Low CVE-2026-96545Gimp: gimp: out-of-bounds heap read in the 4bpp tim image loader Exploitation status Public exploit Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/23/2026 Severity Medium CVE-2026-71462Automation-controller: automation-controller-container: automation-controller: custom_venv_path setting provides filesystem path-existence oracle on control pod Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.5 for RHEL 8 Published 09/23/2026 Severity Medium CVE-2026-71461Automation-controller: automation-controller-container: automation-controller: verbose internal exception disclosure via hostlist bare-exception handler Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.7 Published 09/23/2026 Severity Medium CVE-2026-71460Automation-controller: automation-controller-container: automation-controller: any authenticated user reads red hat subscription/license details via /config/ Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.5 for RHEL 8 Published 09/23/2026 Severity Medium CVE-2026-76648Automation-controller: automation-controller-container: aap controller: copyapiview.post() missing read authorization check enables job template secret recovery Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.7 Published 09/23/2026 Severity High CVE-2026-96541Gnome-remote-desktop: gnome-remote-desktop: unauthenticated rdp sockets lack a handshake deadline Exploitation status Public exploit Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/23/2026 Severity High CVE-2026-71459Automation-controller: automation-controller-container: automation-controller: jobjobeventschildrensummary rbac bypass exposes cross-tenant job event tree structure Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2.5 for RHEL 8 Published 09/23/2026 Severity Medium