Red Hat threat watch

Red Hat product CVE coverage for Enterprise Linux, OpenShift, virtualization, and enterprise platform packages.

Watch items

Recent Red Hat watch items

Showing the 20 most recent items, newest first. Each row links to the official advisory.

20 rows · sorted newest first

Operations view

Red Hat OpenShift AI (RHOAI) MaaS Gateway vulnerability (CVE-2026-13717)

HIGH
watchNVDCVE-2026-13717

A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard user with low privileges to intercept, read, log, and alter all MaaS model traffic. This includes sensitive information such as access keys, input prompts, and outputs, leading to significant information disclosure and data tampering.

Aug 10, 2026, 4:17 PMOfficial source

build of keycloak vulnerability (CVE-2026-18967)

HIGH
watchNVDCVE-2026-18967

A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP-Initiated flow, Keycloak fails to enforce the OneTimeUse condition in SAML assertions. This allows an attacker who captures a valid, unused assertion to replay it multiple times. Successful exploitation could allow an attacker to hijack a user's session and gain unauthorized access to the system as that user.

Aug 6, 2026, 2:16 AMOfficial source

build of keycloak vulnerability (CVE-2026-16442)

CRITICAL
watchNVDCVE-2026-16442

A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs because the IdP-initiated Single Sign-On endpoint fails to check if a provider is restricted to account linking only. This allows an attacker with control over a linked upstream identity to bypass login restrictions and gain full access to a local user account.

Aug 5, 2026, 11:16 AMOfficial source

build of keycloak vulnerability (CVE-2026-16443)

CRITICAL
watchNVDCVE-2026-16443

A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.

Aug 5, 2026, 9:17 AMOfficial source

hardened images vulnerability (CVE-2026-71226)

HIGH
watchNVDCVE-2026-71226

Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.

Aug 5, 2026, 8:24 AMOfficial source

build of keycloak vulnerability (CVE-2026-18571)

HIGH
watchNVDCVE-2026-18571

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-administrator with permission to create users to add those users to any group, even groups the sub-administrator is not authorized to manage. This could lead to unauthorized access to sensitive information or elevated privileges for the newly created users.

Aug 2, 2026, 1:16 AMOfficial source

build of keycloak vulnerability (CVE-2026-18215)

HIGH
watchNVDCVE-2026-18215

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discovered where this restriction is ignored when using the token exchange feature. This means an attacker with a valid Microsoft token from a completely different organization could gain access to the Keycloak realm, potentially accessing sensitive data or performing unauthorized actions.

Jul 31, 2026, 3:16 AMOfficial source

build of keycloak vulnerability (CVE-2026-18214)

HIGH
watchNVDCVE-2026-18214

Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was found where the token exchange feature, which allows swapping a Google token for a Keycloak token, does not check these domain restrictions. This means an attacker with a valid Google account from a different domain could bypass the security check and gain access to the Keycloak realm.

Jul 31, 2026, 3:16 AMOfficial source

Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE) vulnerability (CVE-2026-17107)

HIGH
watchNVDCVE-2026-17107

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds unrestricted impersonation permissions. An authenticated hub principal can inject an Impersonate-Group header to escalate to cluster-admin on every managed cluster.

Jul 24, 2026, 2:16 PMOfficial source

build of keycloak vulnerability (CVE-2026-1609)

HIGH
watchNVDCVE-2026-1609

A flaw was found in Keycloak. When the JSON Web Token (JWT) authorization grant preview feature is enabled and a user account is disabled, Keycloak fails to validate the user’s disabled status during JWT authorization grant processing. A remote attacker with low privileges can exploit this improper access control vulnerability by presenting a valid assertion token from an external identity provider to obtain a JWT for a disabled user. This allows unauthorized access to sensitive resources.

Jul 15, 2026, 8:16 PMOfficial source

Red Hat Advanced Cluster Security for Kubernetes (RHACS) vulnerability (CVE-2026-9165)

HIGH
watchNVDCVE-2026-9165

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a denial of service for the management plane.

Jul 6, 2026, 4:16 AMOfficial source

directory server vulnerability (CVE-2026-11788)

HIGH
watchNVDCVE-2026-11788

A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before using a BER structure, allowing an unauthenticated remote attacker to crash the LDAP server when the system is under memory pressure.

Jun 9, 2026, 9:16 AMOfficial source

openshift container platform vulnerability (CVE-2026-1784)

HIGH
watchNVDCVE-2026-1784

The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.

Jun 2, 2026, 4:16 AMOfficial source

openshift container platform vulnerability (CVE-2026-46579)

HIGH
watchNVDCVE-2026-46579

A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP frontend does not remove `X-SSL-Client-*` headers from incoming requests. This allows an unauthenticated attacker to send plain HTTP requests with crafted `X-SSL-Client-*` headers. As a result, backends relying on these headers for mutual TLS (Transport Layer Security) authentication can be bypassed, enabling the attacker to impersonate client certificate identities.

May 29, 2026, 6:16 AMOfficial source

openshift container platform vulnerability (CVE-2026-4408)

CRITICAL
watchNVDCVE-2026-4408

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execution on the affected system. This issue primarily affects non-standard configurations where the "check password script" is used with %u and the samba-dcerpcd service is started as a system service.

May 28, 2026, 4:16 AMOfficial source

build of keycloak vulnerability (CVE-2026-9793)

HIGH
watchNVDCVE-2026-9793

A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing the configured signature policy. This allows a remote attacker to submit unauthorized claims, leading to a compromise of data integrity within the OpenID Connect (OIDC) authorization flow. While a redirect URI allowlist acts as a compensating control, this vulnerability violates OIDC Core and Financial-grade API (FAPI) signing requirements.

May 28, 2026, 12:16 AMOfficial source

build of keycloak vulnerability (CVE-2026-9704)

HIGH
watchNVDCVE-2026-9704

A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) to the TokenEndpoint. When the token exceeds a 4000-character limit, it is silently dropped, causing the system to fall back to client credentials. This allows the user to gain the permissions of the client's service account, leading to privilege escalation.

May 27, 2026, 9:17 AMOfficial source

openshift container platform vulnerability (CVE-2026-4480)

CRITICAL
watchNVDCVE-2026-4480

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system.

May 26, 2026, 10:16 AMOfficial source

build of keycloak vulnerability (CVE-2026-9087)

HIGH
watchNVDCVE-2026-9087

A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually verified, so a second upstream account on the same IdP can consume it and get linked to the victim's local account.

May 20, 2026, 12:16 PMOfficial source

directory server vulnerability (CVE-2026-9064)

HIGH
watchNVDCVE-2026-9064

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an upper bound on the number of controls per LDAP message. A remote, unauthenticated attacker can send a specially crafted LDAP request containing hundreds of thousands of minimal controls within the default maximum BER message size (2 MB), causing excessive CPU consumption and heap allocation on the server. Under concurrent exploitation, this leads to significant latency degradation, worker thread starvation, or out-of-memory termination, resulting in a denial of service.

May 20, 2026, 5:16 AMOfficial source

Vendor watch hub

What this page covers

The Red Hatwatch hub is a vendor-specific view inside ITECS MSP Threat Radar. We pull the latest security advisories, incidents, and known-exploited CVEs directly from the official feeds below, score each one for MSP relevance, and surface what's most likely to need attention this week.

  • Confirm whether recent Red Hat activity overlaps with your environment.
  • Prioritize advisories by MSP-relevance score, severity, and status.
  • Turn the signal into an assessment, briefing, or managed-service engagement with ITECS.

At a glance

Tracked

196

Active

11

Featured

58

Unique CVEs

20

Most recent entry

Aug 10, 2026, 4:17 PM

Feed refreshes daily · 5:15 a.m. Central

Sources·CISA KEV and NVD (product vendor coverage)

"Most recent entry" is the newest item the upstream feed has published — not our sync time.

Related vendors

Other cloud vendors in the radar

Vendor watch FAQ

Common questions

What is the Red Hat threat watch page?

It is the Red Hat-specific view inside ITECS Threat Radar, built to track recent advisories, incidents, and watch items that may affect Dallas-area business operations.

How should teams use the Red Hat watch page?

Use it to confirm whether current Red Hat issues overlap with your environment, prioritize remediation, and decide whether you need an assessment, managed security follow-through, or vendor-specific hardening work.

Can ITECS help respond to Red Hat security issues?

Yes. ITECS can help map Red Hat advisories against your systems, validate affected services, prioritize remediation, and connect the issue to broader managed cybersecurity or managed IT workflows.