Red Hat
12,500 CVEs tracked since 1999. Since Sep 2021, 29 of them reached CISA KEV.
Red Hat CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-09 | 22 | 4 |
| 2021-10 | 23 | 0 |
| 2021-11 | 30 | 0 |
| 2021-12 | 37 | 3 |
| 2022-01 | 72 | 1 |
| 2022-02 | 53 | 1 |
| 2022-03 | 78 | 2 |
| 2022-04 | 49 | 0 |
| 2022-05 | 49 | 0 |
| 2022-06 | 44 | 0 |
| 2022-07 | 36 | 0 |
| 2022-08 | 130 | 0 |
| 2022-09 | 58 | 0 |
| 2022-10 | 51 | 0 |
| 2022-11 | 45 | 0 |
| 2022-12 | 97 | 0 |
| 2023-01 | 65 | 0 |
| 2023-02 | 59 | 1 |
| 2023-03 | null or fewer | |
| 2023-04 | 37 | 1 |
| 2023-05 | 38 | 0 |
| 2023-06 | 65 | 2 |
| 2023-07 | 72 | 0 |
| 2023-08 | 70 | 1 |
| 2023-09 | 84 | 2 |
| 2023-10 | 78 | 2 |
| 2023-11 | 66 | 0 |
| 2023-12 | 56 | 0 |
| 2024-01 | 77 | 2 |
| 2024-02 | 79 | 0 |
| 2024-03 | 68 | 0 |
| 2024-04 | 210 | 0 |
| 2024-05 | 431 | 0 |
| 2024-06 | 120 | 0 |
| 2024-07 | 220 | 0 |
| 2024-08 | 121 | 0 |
| 2024-09 | 170 | 0 |
| 2024-10 | 212 | 0 |
| 2024-11 | 148 | 3 |
| 2024-12 | 196 | 2 |
| 2025-01 | 128 | 0 |
| 2025-02 | 300 | 0 |
| 2025-03 | 166 | 0 |
| 2025-04 | 130 | 0 |
| 2025-05 | 218 | 0 |
| 2025-06 | 259 | 1 |
| 2025-07 | 294 | 0 |
| 2025-08 | 79 | 0 |
| 2025-09 | 267 | 0 |
| 2025-10 | 337 | 0 |
| 2025-11 | 84 | 0 |
| 2025-12 | 211 | 0 |
| 2026-01 | 111 | 0 |
| 2026-02 | 46 | 0 |
| 2026-03 | 89 | 0 |
| 2026-04 | 73 | 1 |
| 2026-05 | 95 | 0 |
| 2026-06 | 132 | 0 |
| 2026-07 | 164 | 0 |
| 2026-08 | 228 | 0 |
| 2026-09 | 157 | 0 |
Products
The products that kept showing up in Red Hat's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Red Hat.
- CVE-2026-71224Gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk4.7
- CVE-2026-71222Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing5.3
- CVE-2026-71221Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemeta7.0
- CVE-2026-71220Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_edit7.0
- CVE-2026-71219Gfs2-utils: gfs2-utils: stack overflow via alloca(1<<di_depth) in hash table traversal4.7
- CVE-2026-82343Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-count handling6.1
- CVE-2026-82330Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds check6.1
- CVE-2026-82328Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count6.1
- CVE-2026-82324Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch and nplanes=06.1
- CVE-2026-80101Gimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-line validation4.4
- CVE-2026-78475Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader6.1
- CVE-2026-11861Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships9.6
- CVE-2026-73198Ipa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body read7.5
- CVE-2026-13097Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore8.7
- CVE-2026-73196Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encoding4.3
The record
- Peak rank
- #1 in Feb 2014
- Busiest month shown
- May 2024, 431 CVEs
- Months with a KEV entry
- 16 since Sep 2021
- Monthly snapshots
- 290 since 1999