| CVE-2026-15572 | 8.8 | high | redhat / build of keycloak | A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. | 31d ago |
| CVE-2026-5136 | 8.8 | high | redhat / satellite | A flaw was found in Foreman. | 66d ago |
| CVE-2026-12856 | 8.8 | high | redhat / openshift dev spaces | A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. | 68d ago |
| CVE-2026-54099 | 8.8 | high | redhat / openshift container platform | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. | 75d ago |
| CVE-2026-1784 | 8.8 | high | redhat / openshift container platform | The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. | 95d ago |
| CVE-2026-13097 | 8.7 | high | redhat / enterprise linux | A privilege escalation flaw was found in FreeIPA. | 16d ago |
| CVE-2026-12975 | 8.5 | high | redhat / build of apicurio registry | A flaw was found in Apicurio Registry. | 72d ago |
| CVE-2026-54100 | 8.3 | high | redhat / openshift container platform | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. | 75d ago |
| CVE-2026-19550 | 8.2 | high | redhat / enterprise linux | A flaw was found in FreeIPA. | 25d ago |
| CVE-2026-16102 | 8.1 | high | redhat / build of keycloak | A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management | 31d ago |
| CVE-2026-15573 | 8.1 | high | redhat / build of keycloak | A flaw was found in Keycloak's Authorization Services. | 31d ago |
| CVE-2026-1609 | 8.1 | high | redhat / build of keycloak | A flaw was found in Keycloak. | 52d ago |
| CVE-2026-11800 | 8.1 | high | redhat / build of keycloak | A flaw was found in Keycloak. | 72d ago |
| CVE-2026-9800 | 8.1 | high | redhat / build of keycloak | A flaw was found in Keycloak Policy Enforcer. | 72d ago |
| CVE-2026-7504 | 8.1 | high | redhat / build of keycloak | A flaw was found in Keycloak's URL validation logic during redirect operations. | 109d ago |
| CVE-2026-2603 | 8.1 | high | redhat / build of keycloak | A flaw was found in Keycloak. | 172d ago |
| CVE-2026-3012 | 8 | high | redhat / openshift container platform | A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. | 101d ago |
| CVE-2026-42170 | 7.8 | high | redhat / enterprise linux | A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. | 28d ago |
| CVE-2026-12112 | 7.8 | high | redhat / satellite | A flaw was found in the foreman-mcp-server. | 74d ago |
| CVE-2026-9099 | 7.7 | high | redhat / build of keycloak | A flaw was found in Keycloak. | 72d ago |
| CVE-2026-42965 | 7.7 | high | redhat / openshift container platform | A flaw was found in the OpenShift Router. | 99d ago |
| CVE-2026-2092 | 7.7 | high | redhat / build of keycloak | A flaw was found in Keycloak. | 172d ago |
| CVE-2026-18381 | 7.6 | high | redhat / cost management metrics operator | A flaw was found in the koku-metrics-operator for Red Hat OpenShift. | 37d ago |
| CVE-2026-18378 | 7.6 | high | redhat / cost management metrics operator | A flaw was found in koku-metrics-operator. | 37d ago |
| CVE-2026-73198 | 7.5 | high | redhat / enterprise linux | A flaw was found in FreeIPA. | 16d ago |
| CVE-2026-73197 | 7.5 | high | redhat / enterprise linux | A flaw was found in FreeIPA. | 16d ago |
| CVE-2026-15722 | 7.5 | high | redhat / directory server | A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). | 36d ago |
| CVE-2026-11770 | 7.5 | high | redhat / directory server | A flaw was found in 389 Directory Server. | 36d ago |
| CVE-2026-9064 | 7.5 | high | redhat / directory server | A flaw was found in 389-ds-base. | 108d ago |
| CVE-2026-7507 | 7.5 | high | redhat / build of keycloak | A session fixation vulnerability was found in Keycloak's login-actions endpoints. | 109d ago |
| CVE-2026-7307 | 7.5 | high | redhat / build of keycloak | A flaw was found in Keycloak. | 109d ago |
| CVE-2026-16442 | 7.4 | high | redhat / build of keycloak | A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user au | 31d ago |
| CVE-2026-16443 | 7.4 | high | redhat / build of keycloak | A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core e | 31d ago |
| CVE-2026-12992 | 7.4 | high | redhat / build of apicurio registry | A flaw was found in Apicurio Registry. | 72d ago |
| CVE-2026-46579 | 7.4 | high | redhat / openshift container platform | A flaw was found in the OpenShift Router. | 99d ago |
| CVE-2026-71226 | 7.3 | high | redhat / hardened images | Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before al | 31d ago |
| CVE-2026-9086 | 7.3 | high | redhat / build of keycloak | A flaw was found in Keycloak. | 72d ago |
| CVE-2026-9795 | 7.3 | high | redhat / build of keycloak | A flaw was found in Keycloak's Fine-Grained Admin Permissions (FGAPv2) feature. | 100d ago |
| CVE-2026-71474 | 7.1 | high | redhat / advanced cluster management for kubernetes | A flaw was found in insights-client. | 25d ago |
| CVE-2026-13601 | 7.1 | high | redhat / enterprise linux | A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp | 68d ago |
| CVE-2026-1933 | 7.1 | high | redhat / openshift container platform | A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. | 101d ago |
| CVE-2026-7571 | 7.1 | high | redhat / build of keycloak | A flaw was found in Keycloak. | 109d ago |
| CVE-2026-54230 | 7 | high | redhat / automatic bug reporting tool | A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. | 84d ago |