CyberMax
Home › Exploited CVEs

Red Hat known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 9 Red Hat CVEs as exploited in the wild. 2 were added in the last 12 months (latest 2026-08-26), and 4 are known to be used in ransomware campaigns.

Red Hat CVEs added to CISA KEV per year
2021: 2202122022: 3202232023: 2202322026: 220262

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Red Hat products

Polkit (2), JBoss (2), Automatic Bug Reporting Tool (1), Libuser (1), JBoss RichFaces Framework (1), JBoss Application Server (1), JBoss Seam 2 (1).

All Red Hat CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2015-5287Automatic Bug Reporting ToolAutomatic Bug Reporting Tool Privilege Escalation2026-08-262026-09-095.0%–
CVE-2015-3246LibuserLibuser Race Condition2026-08-262026-09-098.8%–
CVE-2018-14667JBoss RichFaces FrameworkJBoss RichFaces Framework Expression Language Injection2023-09-282023-10-1974.2%–
CVE-2021-3560PolkitPolkit Incorrect Authorization2023-05-122023-06-0223.7%–
CVE-2021-4034PolkitPolkit Out-of-Bounds Read and Write2022-06-272022-07-1894.3%Yes
CVE-2010-1428JBossJBoss Information Disclosure2022-05-252022-06-1562.1%Yes
CVE-2010-0738JBossJBoss Authentication Bypass2022-05-252022-06-1579.4%Yes
CVE-2017-12149JBoss Application ServerJBoss Application Server Remote Code Execution2021-12-102022-06-1090.7%Yes
CVE-2010-1871JBoss Seam 2Linux JBoss Seam 2 Remote Code Execution2021-12-102022-06-1083.4%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors