Red Hat Jboss Enterprise Application Platform 7.4 Els On Rhel 7
15 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Red Hat Jboss Enterprise Application Platform 7.4 Els On Rhel 7, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Red Hat Jboss Enterprise Application Platform 7.4 Els On Rhel 7 CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 1 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 1 |
| 2026-01 | 2 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 10 |
| 2026-09 | 1 |
Severity
How the 15 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High13
Latest CVEs
The 15 most recently published vulnerabilities affecting Red Hat Jboss Enterprise Application Platform 7.4 Els On Rhel 7.
- CVE-2026-86404Artemis-server: artemis-jms-client: artemis-core-client: undertow-core: wildfly-messaging-activemq-subsystem: artemis messaging handlers in red hat eap permit deserialization by default8.8
- CVE-2026-15567Wildfly: wildfly-iiop: wildfly-jacorb: wildfly: pre-auth denial of service on the iiop listener7.5
- CVE-2026-15565Undertow: undertow-websockets: undertow: pre-auth dos on websocket endpoint with @serverendpoint class with any @onmessage method7.5
- CVE-2026-15563Wildfly-iiop-openjdk: missing authentication on eap's iiop nameservice leads to mitm or dos7.4
- CVE-2026-15562Jboss-remoting: jboss-remoting: integer overflow in messagereader leads to pre-authentication denial of service7.5
- CVE-2026-15561Undertow-core: oom via missing limits in chunked trailer in eap's undertow7.5
- CVE-2026-15560Openjdk-orb: unauthed class loading via iiop in eap8.1
- CVE-2026-15556Picketlink-federation: picketlink saml 2.0 auth bypass via missing assertions8.1
- CVE-2026-15554Undertow-core: undertow: authentication bypass via ajp ssl_cert/is_ssl forgery7.4
- CVE-2026-15555Jboss-marshalling-river: wildfly-clustering-infinispan-marshalling: jboss deserialization rce via unfiltered river unmarshaller8.8
- CVE-2026-10579Picketlink-federation: auth bypass in picketlink saml unsolicited-response9.8
- CVE-2026-0603Org.hibernate/hibernate-core: hibernate: information disclosure and data deletion via second-order sql injection8.3
- CVE-2025-12543Undertow-core: undertow http server fails to reject malformed host headers leading to potential cache poisoning and ssrf9.6
- CVE-2024-3884Undertow: outofmemory when parsing form data encoding with application/x-www-form-urlencoded7.5
- CVE-2025-9784Undertow: undertow madeyoureset http/2 ddos vulnerability7.5
Product grouping is registry-driven, with AI assist and human review. How it works