Synced 12 Sept 2026 01:32 UTC Account
← Red Hat Enterprise Linux

Red Hat Enterprise Linux vulnerabilities: known CVEs & security history

Red Hat · Operating System · 298 tracked CVEs · 8 actively exploited · updated September 2026 · what is a CVE? →

This is the full list of known vulnerabilities (CVEs) across all Red Hat Enterprise Linux release lines — 298 in total, with 8 actively exploited in the wild. A CVE here doesn't mean your version is affected — check Red Hat Enterprise Linux's current status and the safe version to run.

298
known CVEs
8
actively exploited (KEV)
9
critical severity
2
ransomware-linked

Known Red Hat Enterprise Linux CVEs

Actively-exploited and most-severe first. Showing the top 80 of 298. Open any CVE for full details.

CVESeverityCVSSEPSSYear
CVE-2021-40438⚡ exploited critical 9 100% 2021
CVE-2025-31277⚡ exploited high 8.8 1% 2025
CVE-2026-31431⚡ exploited high 7.8 100% 2026
CVE-2021-4034⚡ exploited high 7.8 95% 2022
CVE-2015-5287⚡ exploited high 7.8 3% 2015
CVE-2026-34486⚡ exploited high 7.5 81% 2026
CVE-2023-44487⚡ exploited high 7.5 100% 2023
CVE-2015-3246⚡ exploited medium 5.1 7% 2015
CVE-2026-53006 critical 9.8 0% 2026
CVE-2026-53002 critical 9.8 0% 2026
CVE-2024-12084 critical 9.8 72% 2025
CVE-2026-11861 critical 9.6 0% 2026
CVE-2026-1709 critical 9.4 5% 2026
CVE-2026-44172 critical 9.1 1% 2026
CVE-2026-4408 critical 9 3% 2026
CVE-2026-4480 critical 9 14% 2026
CVE-2026-59851 high 8.8 0% 2026
CVE-2026-5136 high 8.8 0% 2026
CVE-2026-13097 high 8.7 0% 2026
CVE-2026-28369 high 8.7 1% 2026
CVE-2026-28368 high 8.7 1% 2026
CVE-2023-46847 high 8.6 88% 2023
CVE-2026-59090 high 8.4 1% 2026
CVE-2023-40547 high 8.3 5% 2024
CVE-2026-19550 high 8.2 0% 2026
CVE-2026-35091 high 8.2 1% 2026
CVE-2026-0966 high 8.2 1% 2026
CVE-2026-42055 high 8.1 4% 2026
CVE-2026-9256 high 8.1 10% 2026
CVE-2024-6387 high 8.1 100% 2024
CVE-2024-5154 high 8.1 1% 2024
CVE-2023-4853 high 8.1 1% 2023
CVE-2026-3012 high 8 0% 2026
CVE-2024-1488 high 8 0% 2024
CVE-2026-59087 high 7.8 0% 2026
CVE-2026-42170 high 7.8 0% 2026
CVE-2026-66758 high 7.8 0% 2026
CVE-2026-53153 high 7.8 0% 2026
CVE-2026-53145 high 7.8 0% 2026
CVE-2026-53009 high 7.8 0% 2026
CVE-2026-53000 high 7.8 0% 2026
CVE-2026-50264 high 7.8 0% 2026
CVE-2026-50261 high 7.8 0% 2026
CVE-2026-50260 high 7.8 0% 2026
CVE-2026-50259 high 7.8 0% 2026
CVE-2026-50258 high 7.8 0% 2026
CVE-2026-50257 high 7.8 0% 2026
CVE-2026-50256 high 7.8 0% 2026
CVE-2026-48864 high 7.8 0% 2026
CVE-2026-6846 high 7.8 0% 2026
CVE-2026-4775 high 7.8 1% 2026
CVE-2025-5914 high 7.8 0% 2025
CVE-2025-46397 high 7.8 0% 2025
CVE-2025-0678 high 7.8 0% 2025
CVE-2024-45782 high 7.8 0% 2025
CVE-2025-26601 high 7.8 0% 2025
CVE-2025-26600 high 7.8 0% 2025
CVE-2025-26599 high 7.8 0% 2025
CVE-2025-26598 high 7.8 0% 2025
CVE-2025-26597 high 7.8 0% 2025
CVE-2025-26596 high 7.8 0% 2025
CVE-2025-26595 high 7.8 0% 2025
CVE-2025-26594 high 7.8 0% 2025
CVE-2024-50074 high 7.8 0% 2024
CVE-2024-9675 high 7.8 0% 2024
CVE-2023-6377 high 7.8 2% 2023
CVE-2023-5367 high 7.8 1% 2023
CVE-2022-1055 high 7.8 1% 2022
CVE-2022-0330 high 7.8 0% 2022
CVE-2022-27666 high 7.8 6% 2022
CVE-2022-1011 high 7.8 1% 2022
CVE-2023-6478 high 7.6 2% 2023
CVE-2026-73198 high 7.5 0% 2026
CVE-2026-73197 high 7.5 0% 2026
CVE-2026-19654 high 7.5 0% 2026
CVE-2026-15722 high 7.5 1% 2026
CVE-2026-11770 high 7.5 1% 2026
CVE-2026-58016 high 7.5 1% 2026
CVE-2026-46625 high 7.5 1% 2026
CVE-2025-71319 high 7.5 1% 2026

218 older / lower-severity CVEs not shown — see Red Hat Enterprise Linux's full record.

Is my Red Hat Enterprise Linux version affected?

The list above spans every release. To know whether your version is affected — and the minimum safe version to upgrade to — check it directly.

Check your Red Hat Enterprise Linux version → · Monitor Red Hat Enterprise Linux for new CVEs →

Red Hat Enterprise Linux vulnerabilities — frequently asked

How many known vulnerabilities does Red Hat Enterprise Linux have?

IsItPatched tracks 298 CVEs for Red Hat Enterprise Linux, 8 of which are actively exploited (CISA KEV). 9 are critical-severity and 115 high-severity. These span every release line — what matters is whether the version you run is affected.

Does Red Hat Enterprise Linux have any actively-exploited vulnerabilities?

Yes — 8 Red Hat Enterprise Linux CVEs are in CISA's Known Exploited Vulnerabilities catalog, meaning they are confirmed exploited in the wild (2 linked to ransomware). Patch these as a priority.

What is the most severe Red Hat Enterprise Linux vulnerability?

Among tracked issues, CVE-2021-40438 (CRITICAL, CVSS 9), which is actively exploited, ranks highest — a Server-side request forgery (SSRF) weakness.

Is Red Hat Enterprise Linux safe to use?

It depends on the version. The latest supported Red Hat Enterprise Linux release (10.2) clears the known issues; older versions may still be affected. Check the exact version you run for a verdict.

CVE data aggregated from NVD, CISA KEV and EPSS (FIRST.org). Related: Red Hat Enterprise Linux security status · Red Hat Enterprise Linux end-of-life · actively-exploited CVEs. Always verify against Red Hat's advisories — see our disclaimer.