Red Hat known exploited vulnerabilities
CISA lists 9 Red Hat CVEs as exploited in the wild. 2 were added in the last 12 months (latest 2026-08-26), and 4 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2021-4034 (Polkit): EPSS 94.3%, added 2022-06-27
- CVE-2017-12149 (JBoss Application Server): EPSS 90.7%, added 2021-12-10
- CVE-2010-1871 (JBoss Seam 2): EPSS 83.4%, added 2021-12-10
- CVE-2010-0738 (JBoss): EPSS 79.4%, added 2022-05-25
- CVE-2018-14667 (JBoss RichFaces Framework): EPSS 74.2%, added 2023-09-28
Most affected Red Hat products
Polkit (2), JBoss (2), Automatic Bug Reporting Tool (1), Libuser (1), JBoss RichFaces Framework (1), JBoss Application Server (1), JBoss Seam 2 (1).
All Red Hat CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2015-5287 | Automatic Bug Reporting Tool | Automatic Bug Reporting Tool Privilege Escalation | 2026-08-26 | 2026-09-09 | 5.0% | – |
| CVE-2015-3246 | Libuser | Libuser Race Condition | 2026-08-26 | 2026-09-09 | 8.8% | – |
| CVE-2018-14667 | JBoss RichFaces Framework | JBoss RichFaces Framework Expression Language Injection | 2023-09-28 | 2023-10-19 | 74.2% | – |
| CVE-2021-3560 | Polkit | Polkit Incorrect Authorization | 2023-05-12 | 2023-06-02 | 23.7% | – |
| CVE-2021-4034 | Polkit | Polkit Out-of-Bounds Read and Write | 2022-06-27 | 2022-07-18 | 94.3% | Yes |
| CVE-2010-1428 | JBoss | JBoss Information Disclosure | 2022-05-25 | 2022-06-15 | 62.1% | Yes |
| CVE-2010-0738 | JBoss | JBoss Authentication Bypass | 2022-05-25 | 2022-06-15 | 79.4% | Yes |
| CVE-2017-12149 | JBoss Application Server | JBoss Application Server Remote Code Execution | 2021-12-10 | 2022-06-10 | 90.7% | Yes |
| CVE-2010-1871 | JBoss Seam 2 | Linux JBoss Seam 2 Remote Code Execution | 2021-12-10 | 2022-06-10 | 83.4% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors