Where
AND
-Infinity
0

Vendor Risk Score

See how red hat compares to other vendors in security performance

View Risk Score →

Software

red hat red hat enterprise linux for x86_64 - update services for sap solutions
20
red hat red hat enterprise linux server for power le - update services for sap solutions
20
red hat red hat enterprise linux for power, little endian - extended update support
19
red hat red hat enterprise linux for x86_64 - extended life cycle
19
red hat red hat enterprise linux for x86_64 - extended update support
19
red hat red hat enterprise linux for power, little endian - extended life cycle
18
red hat openshift container platform
17
red hat red hat enterprise linux for arm 64
17
red hat red hat enterprise linux for x86_64
17
red hat red hat openshift container platform
17
red hat red hat enterprise linux for arm 64 - 4 years of updates
16
red hat red hat enterprise linux for arm 64 - extended update support
16
red hat red hat enterprise linux for ibm z systems - 4 years of updates
16
red hat red hat enterprise linux for ibm z systems - extended update support
16
red hat red hat enterprise linux for power, little endian
16
red hat red hat enterprise linux server - aus
16
red hat red hat enterprise linux for ibm z systems
14
red hat red hat enterprise linux for arm 64 - extended life cycle
13
red hat red hat enterprise linux for ibm z systems - extended life cycle
13
red hat red hat ansible automation platform
10
red hat red hat openshift container platform for arm 64
10
red hat red hat openshift container platform for ibm z and linuxone
10
red hat red hat openshift container platform for power
10
red hat advanced cluster management for kubernetes
8
red hat red hat openshift ai
8
red hat multicluster engine for kubernetes
7
red hat enterprise linux for power, little endian - extended update support
6
red hat enterprise linux server
6
red hat multicluster engine
6
red hat multicluster global hub
6
red hat red hat codeready linux builder for arm 64
6
red hat red hat codeready linux builder for power, little endian
6
red hat red hat codeready linux builder for x86_64
6
red hat red hat enterprise linux for power, little endian - 4 years of support
6
red hat red hat enterprise linux for x86_64 - 4 years of updates
6
red hat red hat satellite
6
red hat enterprise linux server for ibm z systems
5
red hat openshift
5
red hat red hat ai inference server
5
red hat red hat codeready linux builder for arm 64 - extended update support
5
red hat red hat codeready linux builder for ibm z systems
5
red hat red hat codeready linux builder for ibm z systems - extended update support
5
red hat red hat codeready linux builder for power, little endian - extended update support
5
red hat red hat codeready linux builder for x86_64 - extended update support
5
red hat red hat openshift service mesh
5
red hat enterprise linux for sap solutions
4
red hat enterprise linux server for power le - update services for sap solutions
4
red hat enterprise linux 8
3
red hat enterprise linux for arm64 eus
3
red hat enterprise linux for x86_64 - extended update support
3
Severity
9

Critical: Multicluster Global Hub 1.4.8 security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Critical: Multicluster Global Hub 1.5.7 security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Critical: Multicluster Global Hub 1.6.5 security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

OpenShift Container Platform 4.16.68 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated user, referred to as a tenant, to manipulate the GitOpsCluster controller. By exploiting this, a tenant can redirect sensitive spoke cluster bearer tokens from secure locations to a namespace they control. This unauthorized access to tokens can lead to the disclosure of critical information and bypass security policies within ArgoCD AppProjects.

1 / 2
Source: NVD
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Severity
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

A flaw was found in the multicloud-integrations component of Red Hat Advanced Cluster Management (RHACM). The Application propagation controller takes the tenant-controlled ocm-managed-cluster annotation verbatim from an Application CR and uses it as the ManifestWork namespace without authorization checks. The only validation is a bare existence check on the target ManagedCluster. A tenant with Application create permissions in any hub namespace can generate ManifestWorks targeting arbitrary managed clusters, resulting in spoke cluster-admin ArgoCD syncing attacker-controlled manifests.

Upstream repo: https://github.com/stolostron/multicloud-integrations Audited commit: d88a168 Jira tracker: ACM-38643

1 / 2
Source: Red Hat
First published (updated )
Severity
9.9
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). The application-manager addon's ClusterRole grants apiGroups: resources: verbs: (plus nonResourceURLs:) and is bound to the application-manager ServiceAccount on every managed cluster via the addon framework. This wildcard RBAC is the root enabler for multiple confused-deputy attacks where a namespace-admin tenant can create Subscription CRs that deploy arbitrary cluster-scoped resources using this privileged SA. A least-privilege variant exists in addon/manifests/permission/role.yaml but is not used by default.

Upstream repo: https://github.com/stolostron/multicloud-operators-subscription Audited commit: 48ae4defaa5b719e0664e1de7413c96029c938bc Jira tracker: ACM-38624

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Release of RHOAI 3.3.6 provides these changes:

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Release of RHOAI 3.4.3 provides these changes:

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Release of RHOAI 2.25.10 provides these changes:

1 / 2
Source: Red Hat
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Severity
9

Critical: Multicluster Global Hub 1.7.2 security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Critical: Multicluster Global Hub 1.8.1 security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

OpenShift Container Platform 4.17.56 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

OpenShift Container Platform 4.19.41 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

OpenShift Container Platform 4.18.51 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Severity
9

OpenShift Container Platform 4.22.8 bug fix and security update

First published (updated )
Severity
9

OpenShift Container Platform 4.20.32 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

OpenShift Container Platform 4.21.27 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Critical: perl-GD security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9.3
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers to gain administrative access by using default credentials identical across all installations. Attackers can authenticate to the exposed WildFly management console on port 20990 and deploy a malicious Web Application Archive file through the Deployments interface to achieve remote code execution as the Windows machine account. Version 14.x.x was declared end-of-life (EOL) in 2017 and future releases have addressed the vulnerable finding.

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Severity
9

Critical: multicluster engine for Kubernetes v2.8.9 security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Critical: multicluster engine for Kubernetes v2.9.6 security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Critical: multicluster engine for Kubernetes v2.6.13 security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Critical: multicluster engine for Kubernetes v2.11.4 security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Critical: multicluster engine for Kubernetes v2.17.1 security update

1 / 2
Source: Red Hat
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Severity
9

Critical: OpenShift Container Platform 4.22.7 bug fix and security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Critical: multicluster engine for Kubernetes v2.10.4 security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9

Critical: multicluster engine for Kubernetes v2.10.4 security update

1 / 2
Source: Red Hat
First published (updated )
Severity
9.1
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attributes for keys, the system incorrectly disables signature validation for SAML responses even if a signing certificate is provided. This issue allows an unauthenticated attacker to forge a SAML response and gain unauthorized access to a user account by knowing their external identifier.

1 / 2
Source: MITRE
First published (updated )
Severity
9

Migration Toolkit for Applications

1 / 2
Source: Red Hat
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203