Red Hat Enterprise Linux vulnerabilities: known CVEs & security history
Red Hat · Operating System · 201 tracked CVEs · 3 actively exploited · updated August 2026 · what is a CVE? →
This is the full list of known vulnerabilities (CVEs) across all Red Hat Enterprise Linux release lines — 201 in total, with 3 actively exploited in the wild. A CVE here doesn't mean your version is affected — check Red Hat Enterprise Linux's current status and the safe version to run.
Known Red Hat Enterprise Linux CVEs
Actively-exploited and most-severe first. Showing the top 80 of 201. Open any CVE for full details.
| CVE | Severity | CVSS | EPSS | Year |
|---|---|---|---|---|
| CVE-2021-40438⚡ exploited | critical | 9 | 100% | 2021 |
| CVE-2025-31277⚡ exploited | high | 8.8 | 1% | 2025 |
| CVE-2026-31431⚡ exploited | high | 7.8 | 95% | 2026 |
| CVE-2026-53006 | critical | 9.8 | 0% | 2026 |
| CVE-2026-53002 | critical | 9.8 | 0% | 2026 |
| CVE-2024-12084 | critical | 9.8 | 72% | 2025 |
| CVE-2026-1709 | critical | 9.4 | 5% | 2026 |
| CVE-2026-44172 | critical | 9.1 | 1% | 2026 |
| CVE-2026-4408 | critical | 9 | 3% | 2026 |
| CVE-2026-4480 | critical | 9 | 13% | 2026 |
| CVE-2026-59851 | high | 8.8 | 0% | 2026 |
| CVE-2026-5136 | high | 8.8 | 0% | 2026 |
| CVE-2026-28369 | high | 8.7 | 1% | 2026 |
| CVE-2026-28368 | high | 8.7 | 1% | 2026 |
| CVE-2023-40547 | high | 8.3 | 5% | 2024 |
| CVE-2025-5318 | high | 8.1 | 2% | 2025 |
| CVE-2026-3012 | high | 8 | 0% | 2026 |
| CVE-2026-53153 | high | 7.8 | 0% | 2026 |
| CVE-2026-53145 | high | 7.8 | 0% | 2026 |
| CVE-2026-53009 | high | 7.8 | 0% | 2026 |
| CVE-2026-53000 | high | 7.8 | 0% | 2026 |
| CVE-2026-50264 | high | 7.8 | 0% | 2026 |
| CVE-2026-50261 | high | 7.8 | 0% | 2026 |
| CVE-2026-50260 | high | 7.8 | 0% | 2026 |
| CVE-2026-50259 | high | 7.8 | 0% | 2026 |
| CVE-2026-50258 | high | 7.8 | 0% | 2026 |
| CVE-2026-50257 | high | 7.8 | 0% | 2026 |
| CVE-2026-50256 | high | 7.8 | 0% | 2026 |
| CVE-2026-48864 | high | 7.8 | 0% | 2026 |
| CVE-2026-6846 | high | 7.8 | 0% | 2026 |
| CVE-2026-4775 | high | 7.8 | 1% | 2026 |
| CVE-2025-5914 | high | 7.8 | 0% | 2025 |
| CVE-2025-46397 | high | 7.8 | 0% | 2025 |
| CVE-2025-0678 | high | 7.8 | 0% | 2025 |
| CVE-2024-45782 | high | 7.8 | 0% | 2025 |
| CVE-2025-26601 | high | 7.8 | 0% | 2025 |
| CVE-2025-26600 | high | 7.8 | 0% | 2025 |
| CVE-2025-26599 | high | 7.8 | 0% | 2025 |
| CVE-2025-26598 | high | 7.8 | 0% | 2025 |
| CVE-2025-26597 | high | 7.8 | 0% | 2025 |
| CVE-2025-26596 | high | 7.8 | 0% | 2025 |
| CVE-2025-26595 | high | 7.8 | 0% | 2025 |
| CVE-2025-26594 | high | 7.8 | 0% | 2025 |
| CVE-2024-9675 | high | 7.8 | 0% | 2024 |
| CVE-2023-6377 | high | 7.8 | 2% | 2023 |
| CVE-2023-5367 | high | 7.8 | 1% | 2023 |
| CVE-2022-1055 | high | 7.8 | 1% | 2022 |
| CVE-2023-6478 | high | 7.6 | 2% | 2023 |
| CVE-2026-58016 | high | 7.5 | 0% | 2026 |
| CVE-2025-71319 | high | 7.5 | 1% | 2026 |
| CVE-2026-9064 | high | 7.5 | 1% | 2026 |
| CVE-2026-42009 | high | 7.5 | 1% | 2026 |
| CVE-2026-33845 | high | 7.5 | 1% | 2026 |
| CVE-2026-5201 | high | 7.5 | 1% | 2026 |
| CVE-2026-5121 | high | 7.5 | 1% | 2026 |
| CVE-2026-4424 | high | 7.5 | 1% | 2026 |
| CVE-2026-3497 | high | 7.5 | 2% | 2026 |
| CVE-2025-9784 | high | 7.5 | 2% | 2025 |
| CVE-2025-7424 | high | 7.5 | 1% | 2025 |
| CVE-2025-6021 | high | 7.5 | 1% | 2025 |
| CVE-2025-3891 | high | 7.5 | 1% | 2025 |
| CVE-2024-12085 | high | 7.5 | 9% | 2025 |
| CVE-2023-52355 | high | 7.5 | 2% | 2024 |
| CVE-2023-4692 | high | 7.5 | 1% | 2023 |
| CVE-2025-3155 | high | 7.4 | 11% | 2025 |
| CVE-2026-58384 | high | 7.3 | 0% | 2026 |
| CVE-2026-58380 | high | 7.3 | 0% | 2026 |
| CVE-2026-58014 | high | 7.3 | 0% | 2026 |
| CVE-2026-41082 | high | 7.3 | 0% | 2026 |
| CVE-2026-6384 | high | 7.3 | 0% | 2026 |
| CVE-2025-62230 | high | 7.3 | 0% | 2025 |
| CVE-2025-62231 | high | 7.3 | 0% | 2025 |
| CVE-2026-13601 | high | 7.1 | 0% | 2026 |
| CVE-2026-1933 | high | 7.1 | 1% | 2026 |
| CVE-2026-42010 | high | 7.1 | 1% | 2026 |
| CVE-2026-26103 | high | 7.1 | 0% | 2026 |
| CVE-2026-54230 | high | 7 | 0% | 2026 |
| CVE-2025-2784 | high | 7 | 1% | 2025 |
| CVE-2023-5574 | high | 7 | 1% | 2023 |
| CVE-2023-3640 | high | 7 | 1% | 2023 |
121 older / lower-severity CVEs not shown — see Red Hat Enterprise Linux's full record.
Is my Red Hat Enterprise Linux version affected?
The list above spans every release. To know whether your version is affected — and the minimum safe version to upgrade to — check it directly.
Check your Red Hat Enterprise Linux version → · Monitor Red Hat Enterprise Linux for new CVEs →
Red Hat Enterprise Linux vulnerabilities — frequently asked
How many known vulnerabilities does Red Hat Enterprise Linux have?
IsItPatched tracks 201 CVEs for Red Hat Enterprise Linux, 3 of which are actively exploited (CISA KEV). 8 are critical-severity and 72 high-severity. These span every release line — what matters is whether the version you run is affected.
Does Red Hat Enterprise Linux have any actively-exploited vulnerabilities?
Yes — 3 Red Hat Enterprise Linux CVEs are in CISA's Known Exploited Vulnerabilities catalog, meaning they are confirmed exploited in the wild (1 linked to ransomware). Patch these as a priority.
What is the most severe Red Hat Enterprise Linux vulnerability?
Among tracked issues, CVE-2021-40438 (CRITICAL, CVSS 9), which is actively exploited, ranks highest — a Server-side request forgery (SSRF) weakness.
Is Red Hat Enterprise Linux safe to use?
It depends on the version. The latest supported Red Hat Enterprise Linux release (10.2) clears the known issues; older versions may still be affected. Check the exact version you run for a verdict.
CVE data aggregated from NVD, CISA KEV and EPSS (FIRST.org). Related: Red Hat Enterprise Linux security status · Red Hat Enterprise Linux end-of-life · actively-exploited CVEs. Always verify against Red Hat's advisories — see our disclaimer.