Red Hat vulnerabilities
24 CVEs tracked
In this reporting period, Red Hat appears primarily in the context of its OpenShift ecosystem, facing significant privilege escalation and authentication bypass issues. Key events include an authentication bypass in the OpenShift AI web console (CVE-2026-16745) via arbitrary tokens, traffic manipulation in MaaS Gateway (CVE-2026-13717), and excessive ServiceAccount permissions (CVE-2026-15218), along with authorization flaws enabling privilege escalation in Azure Red Hat OpenShift (CVE-2026-56160) and RHACM's service-proxy (CVE-2026-17107). Defenders should urgently patch and verify configurations to mitigate CVE-2026-16745 allowing user impersonation within the cluster, CVE-2026-17107 enabling header injection for privilege escalation, and CVE-2026-18107 which could lead to container escape via CRIU.
Azərbaycanca: Hesabat dövründə Red Hat, xüsusilə OpenShift ekosistemində ciddi imtiyaz yüksəltmə (privilege escalation) və autentifikasiyadan yayınma problemləri ilə diqqət çəkir. Əsas hadisələr OpenShift AI (RHOAI) komponentlərində aşkarlanan autentifikasiya bypass (CVE-2026-16745), trafik manipulyasiyası (CVE-2026-13717) və həddindən artıq icazələr (CVE-2026-15218), eləcə də Azure Red Hat OpenShift (CVE-2026-56160) və RHACM-də imtiyaz yüksəltmə imkanlarıdır. Müdafiəçilər xüsusilə CVE-2026-16745 (saxta token ilə istənilən istifadəçini təqlid etmə), CVE-2026-17107 (impersonation qrup başlıqlarının manipulyasiyası) və kontainer qaçışına səbəb ola biləcək CVE-2026-18107-yə qarşı təcili tədbirlər görməlidir.
This vendor's CVEs24
- CVE-2026-74247EPSS 0.14%
- CVE-2026-74245EPSS 0.30%
- CVE-2026-74244EPSS 0.14%
- CVE-2026-74243EPSS 0.27%
- CVE-2026-74242EPSS 0.26%
- CVE-2026-74241EPSS 0.18%
- CVE-2026-74240EPSS 0.17%
- CVE-2026-73122EPSS 0.27%
- CVE-2026-70398EPSS 0.32%
- CVE-2026-66783EPSS 0.13%
- CVE-2026-56160EPSS 0.58%
- CVE-2026-18963EPSS 3%
- CVE-2026-18951EPSS 0.57%
- CVE-2026-18570EPSS 0.14%
- CVE-2026-18569EPSS 0.16%
- CVE-2026-18381EPSS 0.19%
- CVE-2026-18378EPSS 0.23%
- CVE-2026-18107EPSS 0.11%
- CVE-2026-17107EPSS 0.35%
- CVE-2026-16910EPSS 0.21%
- CVE-2026-16745EPSS 0.44%
- CVE-2026-15218EPSS 0.54%
- CVE-2026-13717EPSS 0.37%
- CVE-2026-10090EPSS 0.36%
This hub is built from skopnix's own reporting on Red Hat: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.