CVE Tools

Red Hat

12,500 CVEs tracked since 1999. Since Sep 2021, 29 of them reached CISA KEV.

Red Hat CVEs per month

Sep 2021 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Red Hat CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-09224
2021-10230
2021-11300
2021-12373
2022-01721
2022-02531
2022-03782
2022-04490
2022-05490
2022-06440
2022-07360
2022-081300
2022-09580
2022-10510
2022-11450
2022-12970
2023-01650
2023-02591
2023-03null or fewer
2023-04371
2023-05380
2023-06652
2023-07720
2023-08701
2023-09842
2023-10782
2023-11660
2023-12560
2024-01772
2024-02790
2024-03680
2024-042100
2024-054310
2024-061200
2024-072200
2024-081210
2024-091700
2024-102120
2024-111483
2024-121962
2025-011280
2025-023000
2025-031660
2025-041300
2025-052180
2025-062591
2025-072940
2025-08790
2025-092670
2025-103370
2025-11840
2025-122110
2026-011110
2026-02460
2026-03890
2026-04731
2026-05950
2026-061320
2026-071640
2026-082280
2026-091570

Products

The products that kept showing up in Red Hat's monthly top three, with their CVEs summed over those months.

  1. Red Hat Enterprise Linux5,10252 months
  2. Red Hat Enterprise Linux 997836 months
  3. Red Hat Enterprise Linux 877526 months
  4. Red Hat Enterprise Linux 1036711 months
  5. Red Hat Enterprise Linux 72567 months
  6. Enterprise Linux22916 months
  7. Red Hat Enterprise Linux 6864 months
  8. Red Hat Software Collections837 months
  9. Openshift Container Platform162 months
  10. Enterprise Linux For Power Little Endian141 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Red Hat.

  1. CVE-2026-71224Gfs2-utils: gfs2-utils: stack overflow via alloca(i_height) in metadata walk4.7
  2. CVE-2026-71222Gfs2-utils: gfs2-utils: heap out-of-bounds read via unchecked ea_num_ptrs in extended attribute processing5.3
  3. CVE-2026-71221Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked height in savemeta7.0
  4. CVE-2026-71220Gfs2-utils: gfs2-utils: stack out-of-bounds write via unchecked di_height in gfs2_edit7.0
  5. CVE-2026-71219Gfs2-utils: gfs2-utils: stack overflow via alloca(1<<di_depth) in hash table traversal4.7
  6. CVE-2026-82343Gimp: heap out-of-bounds read and stack out-of-bounds access in psd loader from channel-count handling6.1
  7. CVE-2026-82330Gimp: heap out-of-bounds read in pvr vq (compressed) decoder due to missing bounds check6.1
  8. CVE-2026-82328Gimp: heap out-of-bounds read in ico loader via unvalidated used_clrs palette count6.1
  9. CVE-2026-82324Gimp: heap out-of-bounds reads in iff/ilbm loader from ham row size mismatch and nplanes=06.1
  10. CVE-2026-80101Gimp: multiple heap out-of-bounds reads in xwd loader from unrelated width and bytes-per-line validation4.4
  11. CVE-2026-78475Gimp: unbounded stack vla and 21-byte stack over-read in pix (esm) loader6.1
  12. CVE-2026-11861Freeipa: idm: ipa: freeipa: obtaining tgs with impersonating cname through trust relationships9.6
  13. CVE-2026-73198Ipa: freeipa: unauthenticated dos in `/ipa/i18n_messages` via unbounded request body read7.5
  14. CVE-2026-13097Ipa: privilege escalation via krbcanonicalname manipulation due to realm-unaware uniqueness enforcement in freeipa ldap datastore8.7
  15. CVE-2026-73196Ipa: freeipa: authenticated dos in `otptoken-add` via unbounded otp key decoding/re-encoding4.3

The record

Peak rank
#1 in Feb 2014
Busiest month shown
May 2024, 431 CVEs
Months with a KEV entry
16 since Sep 2021
Monthly snapshots
290 since 1999
Red Hat's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store