CVE-2026-89060Stolostron/multicluster-observability-addon: cross-namespace secret disclosure in multicluster-observability-addon via unvalidated configuration references Exploitation status Not confirmed Fix Not confirmed Affected product R Red Hat Advanced Cluster Management for Kubernetes 2 Published 09/11/2026 Severity High CVE-2026-88914Gstreamer1-plugins-good: gstreamer: integer overflow and out-of-bounds read in qtdemux cea-608 closed-caption parser Exploitation status Not confirmed Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/11/2026 Severity Medium CVE-2026-88924Gvfs: gvfs-admin socket ownership race permits local root Exploitation status Public exploit Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/10/2026 Severity High CVE-2026-88859Evolution: evolution: javascript execution via spoofed vcard control bypasses mail script-markup restriction Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 7 Published 09/10/2026 Severity Medium CVE-2026-84828Pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth --token Exploitation status Not confirmed Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/10/2026 Severity Medium CVE-2026-88265Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and chown Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Hardened Images Published 09/10/2026 Severity Medium CVE-2026-88264Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Hardened Images Published 09/10/2026 Severity Medium CVE-2026-84042Crun: crun: rootful krun with passt executes container payload as host root Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Hardened Images Published 09/10/2026 Severity High CVE-2026-88770Keycloak-services: keycloak-services: device authorization grant issues tokens to brute-force-locked accounts Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Build of Keycloak Published 09/10/2026 Severity Medium CVE-2026-88763Skupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial of service Exploitation status Not confirmed Fix Not confirmed Affected product R Red Hat Service Interconnect 2 Published 09/10/2026 Severity Medium CVE-2026-18147Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrary code execution via crafted url Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/09/2026 Severity High CVE-2026-87876Cups: openprinting cups: remaining case-insensitive username matching in scheduler side paths (cve-2026-27447 follow-up) Exploitation status Public exploit Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/09/2026 Severity Low CVE-2026-87872Community.general: community.general: ocapi module_utils (ocapi_command, ocapi_info) hardcode validate_certs=false with no override, enabling tls man-in-the-middle and credential disclosure Exploitation status Not confirmed Fix Not confirmed Affected product R Red Hat Ceph Storage 5 Published 09/09/2026 Severity Medium CVE-2026-87875Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-length bound Exploitation status Public exploit Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/09/2026 Severity Medium CVE-2026-87853Sssd: sssd: idp authentication prefix comparison allows cross-user impersonation Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/09/2026 Severity High CVE-2026-87874Community.general: community.general: memcached cache plugin deserializes untrusted pickle data from memcached, enabling cache-poisoning remote code execution on the ansible controller Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ceph Storage 5 Published 09/09/2026 Severity High CVE-2026-87766Bubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files outside sandbox during setup Exploitation status Not known exploited Fix YesAffected product R Red Hat Enterprise Linux 10 Published 09/09/2026 Severity High CVE-2026-19729Keycloak-services: keycloak-services: incomplete fix for arbitrary filesystem path probing via keystore parameters Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Build of Keycloak Published 09/09/2026 Severity Medium CVE-2026-86564Dpdk: dpdk: missing length validation before reading command_data in virtio-net control queue handler Exploitation status Not known exploited Fix Not confirmed Affected product F Fast Datapath for RHEL 10 Published 09/08/2026 Severity Low CVE-2026-18090Gdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted icns rle block Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 09/08/2026 Severity Medium CVE-2026-80219Hawtio-operator: hawtio-operator: oauthclient created with grantmethod auto and no secret enables oauth token theft Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat build of Apache Camel - HawtIO 4 Published 09/08/2026 Severity High CVE-2026-78234Hawtio-operator: hawtio-operator: service-ca signing oracle allows arbitrary-cn certificate issuance to namespace edit users Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat build of Apache Camel - HawtIO 4 Published 09/08/2026 Severity Critical CVE-2026-77968Hawtio-operator: hawtio-operator: cluster-wide secrets read/write granted to operator serviceaccount Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat build of Apache Camel - HawtIO 4 Published 09/08/2026 Severity High CVE-2026-74860Libxml2: double-free/uaf in libxml2 python bindings Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Hardened Images Published 09/08/2026 Severity High CVE-2026-74859Gnome-tweaks: path traversal in theme installer Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 8 Published 09/08/2026 Severity Medium CVE-2026-76561Pki-core: dogtag/pki: certprofile-import allows code execution via unsanitized profile content (externalprocessconstraint) Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Certificate System 9 Published 09/08/2026 Severity High CVE-2026-86469Glib2: toctou symlink race in `g_file_create_replace_destination` fallback path Exploitation status Public exploit Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/07/2026 Severity Medium CVE-2026-19843389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editor Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Directory Server 11.7 E4S for RHEL 8 Published 09/07/2026 Severity High CVE-2026-18922389-ds-base: 389-ds-base: sasl plain authentication allows privilege escalation to directory manager via stale identity in cyrus sasl auxiliary property Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Directory Server 11.7 E4S for RHEL 8 Published 09/07/2026 Severity Critical CVE-2026-18453389-ds-base: 389-ds-base: pre-authentication null pointer dereference via paged results and use_one_backend control in op_shared_search Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Directory Server 11.7 E4S for RHEL 8 Published 09/07/2026 Severity High CVE-2026-18355389-ds-base: 389-ds-base: heap buffer overflow via sasl wrapped-record length lower-bound underflow in sasl_io_start_packet() Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Directory Server 11.7 E4S for RHEL 8 Published 09/07/2026 Severity High CVE-2026-76560389-ds-base: 389-ds: anonymous ldap client can defeat selfdn aci bind-rule checks via empty bind dn Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Directory Server 11.7 E4S for RHEL 8 Published 09/07/2026 Severity High CVE-2026-79678Freeipa: idm: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/07/2026 Severity High CVE-2026-76578Ipa: freeipa: freeipa: unauthenticated ldap client can obtain administrator credentials via the self-managed-token aci Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/07/2026 Severity Critical CVE-2026-86404Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging-activemq-subsystem: artemis messaging handlers in red hat eap permit deserialization by default Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 Published 09/07/2026 Severity High CVE-2026-86332Odh-dashboard: odh-dashboard: nim credential secret readable by any authenticated user Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat OpenShift AI (RHOAI) Published 09/07/2026 Severity Medium CVE-2026-76925Flatpak: flatpak: toctou race condition allows symlink redirection Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/04/2026 Severity Medium CVE-2026-85769Libtpms: libtpms: heap out-of-bounds read in tpm2 state unmarshalling via unchecked block_skip_read() blocksize Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/04/2026 Severity Medium CVE-2026-85534Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during deferred body read Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/04/2026 Severity Medium CVE-2026-81666Corosync: corosync: integer overflow in check_memb_commit_token_sanity may bypass message length validation on 32-bit systems Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/04/2026 Severity Medium CVE-2026-81665Corosync: corosync: heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/04/2026 Severity High CVE-2026-85197Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read() via goaway during body upload Exploitation status Public exploit Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/04/2026 Severity High CVE-2026-84185Jwcrypto: jwcrypto: general json jws kid binding bypass during jwkset verification Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2 Published 09/03/2026 Severity Medium CVE-2026-71224Gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 7 Published 09/03/2026 Severity Medium CVE-2026-71222Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 7 Published 09/03/2026 Severity Medium CVE-2026-71221Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemeta Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 7 Published 09/03/2026 Severity High CVE-2026-71220Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_edit Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 7 Published 09/03/2026 Severity High CVE-2026-71219Gfs2-utils: gfs2-utils: stack overflow via alloca(1<<di_depth) in hash table traversal Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 7 Published 09/03/2026 Severity Medium CVE-2026-85150Gstreamer1-plugins-base: gstreamer: null/invalid-pointer dereference in gst_rtsp_message_parse_auth_credentials() when parsing a crafted digest authorization/www-authenticate header Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/03/2026 Severity High CVE-2026-66786Submariner: submariner: ipsec.conf stanza injection via remote-supplied cablename and subnets Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Advanced Cluster Management for Kubernetes 2.17 Published 09/02/2026 Severity Critical CVE-2026-84838Rpm: command injection in rpmuncompress via unescaped filenames passed to popen() Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/02/2026 Severity High CVE-2026-84837Rpm: command injection in `rpmbuild -t*` (`gettarspec`) via unescaped tarball path Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/02/2026 Severity High CVE-2026-78409Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape via intermediate symlinks Exploitation status Public exploit Fix Not confirmed Affected product R Red Hat Hardened Images Published 09/02/2026 Severity High CVE-2026-78410Util-linux: util-linux: restricted bind mounts do not pin the source, allowing x-mount.owner/group/mode redirection Exploitation status Public exploit Fix Not confirmed Affected product R Red Hat Hardened Images Published 09/02/2026 Severity High CVE-2026-78408Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority Exploitation status Public exploit Fix Not confirmed Affected product R Red Hat Hardened Images Published 09/02/2026 Severity High CVE-2026-53683Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/02/2026 Severity Medium CVE-2026-82968Keycloak-services: keycloak-services: cross-session email verification proof not bound to upstream identity for social providers Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Build of Keycloak Published 09/02/2026 Severity Medium CVE-2026-84470Automation-controller: automation-controller-container: automation-controller/awx: bulk job launch checks instance_groups at read level instead of use level, allowing execution-placement authorization bypass Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2 Published 09/01/2026 Severity Medium CVE-2026-49329Openshift/oauth-server: openshift/oauth-server: quadratic-time dos via accept-language header underscore bypass on unauthenticated login endpoints Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat OpenShift Container Platform 4 Published 09/01/2026 Severity High CVE-2026-84270Gvfs: mtp: out-of-bounds read in do_read() Exploitation status Not known exploited Fix YesAffected product R Red Hat Enterprise Linux 10 Published 09/01/2026 Severity Medium CVE-2026-84269Gvfs: afp: heap-based buffer overflow in dsi read path Exploitation status Public exploit Fix YesAffected product R Red Hat Enterprise Linux 10 Published 09/01/2026 Severity Medium CVE-2026-84267Gvfs: sftp: uninitialized heap disclosure in read_string() Exploitation status Public exploit Fix YesAffected product R Red Hat Enterprise Linux 10 Published 09/01/2026 Severity Medium CVE-2026-84232Pulpcore: python-pulpcore: stored cross-site scripting via inline rendering of uploaded html/svg content Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Satellite 6 Published 09/01/2026 Severity Medium CVE-2026-84268Gvfs: sftp: heap-based buffer overflow in read_reply() Exploitation status Not known exploited Fix YesAffected product R Red Hat Enterprise Linux 10 Published 09/01/2026 Severity High CVE-2026-84233Rpm: command execution via macro expansion in `rpmuncompress -x` for crafted `.gem` filenames Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 09/01/2026 Severity High CVE-2026-84218Org.jolokia/jolokia-core: incomplete jndi denylist in jolokia jsr-160 proxy (bypass of cve-2018-1000130 fix) Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat AMQ Broker 7 Published 09/01/2026 Severity High CVE-2026-53682Pki-core: dogtag-pki: unauthenticated dogtag ca rest api exposes security domain hosts Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Certificate System 9 Published 09/01/2026 Severity Medium CVE-2026-11873Pki-core: dogtag-pki: empty request to dogtag /ca/rest/certrequests causes http 500, java exception, and stacktrace disclosure Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Certificate System 9 Published 09/01/2026 Severity Medium CVE-2026-18743Popt-devel: popt-static: short realloc in poptconfigfiletostring Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Hardened Images Published 09/01/2026 Severity Low CVE-2026-83596Webkitgtk: validate the full featurelist array once in opentypeverticaldata findfeature Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 7 Published 08/31/2026 Severity High CVE-2026-13732Gdb: gdb: out-of-bounds write in stabs parser read_member_functions() via crafted elf Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 08/31/2026 Severity High CVE-2026-17615Resteasy-core: resteasy sourceprovider remote unauthenticated file read Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat build of Apache Camel 4 for Quarkus 3 Published 08/31/2026 Severity High CVE-2026-76763Io.smallrye/smallrye-graphql: smallrye graphql: unauthenticated denial of service via large exponent float literals Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat build of Quarkus Published 08/31/2026 Severity High CVE-2026-12894Io.quarkus:quarkus-qute: quarkus-qute:server-side template injection (ssti) vulnerability in reflectionvalueresolver of the quarkus qute template engine Exploitation status Not known exploited Fix YesAffected product R Red Hat build of Apache Camel 4 for Quarkus 3 Published 08/31/2026 Severity High CVE-2026-81624Undertow-core: undertow: websocketcontainer defaults for buffers and timeouts are infinite Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat build of Apache Camel for Spring Boot 4 Published 08/31/2026 Severity High CVE-2026-82343Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-count handling Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 7 Published 08/28/2026 Severity Medium CVE-2026-82330Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds check Exploitation status Public exploit Fix Not confirmed Affected product G GIMP Published 08/28/2026 Severity Medium CVE-2026-82328Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count Exploitation status Public exploit Fix Not confirmed Affected product R Red Hat Enterprise Linux 7 Published 08/28/2026 Severity Medium CVE-2026-82327Libsolv: libsolv: out-of-bounds write in repo_write() via unvalidated directory id from vertical/paged .solv filelist data Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 08/28/2026 Severity Medium CVE-2026-82324Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch and nplanes=0 Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 9 Published 08/28/2026 Severity Medium CVE-2026-18393Ffmpeg: ffmpeg: heap buffer overflow in tdsc_load_cursor() via cur_fmt_mono cursor Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux AI (RHEL AI) 3 Published 08/28/2026 Severity Medium CVE-2026-80179Jwcrypto: jwcrypto: denial of service via malformed jwe tokens Exploitation status Public exploit Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2 Published 08/27/2026 Severity Medium CVE-2026-81893Gdk-pixbuf: gdk-pixbuf: invalid write in jpeg icc profile parser on error recovery Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 08/27/2026 Severity Medium CVE-2026-5680Undertow-core: undertow: denial of service via websocket permessage-deflate processing Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat build of Apache Camel for Spring Boot 4 Published 08/27/2026 Severity High CVE-2026-78002Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() function Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 08/27/2026 Severity High CVE-2026-81668Rubygem-katello: cross-tenant content view filter rule access and modification via unauthorized parent filter lookup Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Satellite 6 Published 08/27/2026 Severity Medium CVE-2026-81658Foreman: cross-tenant disclosure of template revisions via unauthorized audit lookup Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Satellite 6 Published 08/27/2026 Severity Medium CVE-2026-80158Ansible-collection-community-general: community.general: ipa_getkeytab does not set no_log on the bind_pw parameter, disclosing the ipa bind password in logs and process listings Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ceph Storage 5 Published 08/26/2026 Severity Medium CVE-2026-79902Gimp: stack vla size underflow denial of service in seattle Exploitation status Public exploit Fix Not confirmed Affected product G GIMP Published 08/26/2026 Severity Medium CVE-2026-79654Ketello: katello content view history api cross-organization authorization bypass Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Satellite 6 Published 08/26/2026 Severity Medium CVE-2026-80185Bluez: sdp-xml: bluez 5.86: unprivileged-local and adjacent-le-peer leads to arbitrary code execution as root Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 08/25/2026 Severity Medium CVE-2026-80186Bluez: stack overflow in name2utf8 causes dos and potential code execution Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 08/25/2026 Severity High CVE-2026-80101Gimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-line validation Exploitation status Public exploit Fix Not confirmed Affected product R Red Hat Enterprise Linux 7 Published 08/25/2026 Severity Medium CVE-2026-77680Libsoup3: libsoup: quadratic cpu denial of service in http range coalescing after cve-2025-32907 fix Exploitation status Public exploit Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 08/25/2026 Severity Medium CVE-2026-79992Emacs: local shell command injection through the user field in emacs tramp Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 08/25/2026 Severity High CVE-2026-79717Galaxy_ng: galaxy_ng: blind ssrf via namespace avatar_url with no private-address restriction Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Ansible Automation Platform 2 Published 08/25/2026 Severity Medium CVE-2026-79655Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file write Exploitation status Public exploit Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 08/25/2026 Severity High CVE-2026-79652Keycloak-services: keycloak-services: jwt bearer authorization grant does not enforce consentrequired Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Build of Keycloak Published 08/25/2026 Severity Medium CVE-2026-78701389-ds-base: 389-ds-base: cve-2026-11610 incomplete fix may introduce a connection-stall dos Exploitation status Not known exploited Fix Not confirmed Affected product R Red Hat Enterprise Linux 10 Published 08/25/2026 Severity Medium CVE-2026-78322File-roller: file-roller: stack buffer overflow in parse_progress_line for 7z and rar handlers Exploitation status Public exploit Fix Not confirmed Affected product R Red Hat Enterprise Linux 6 Published 08/25/2026 Severity Medium